Description
LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sun, 13 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access. | |
| Title | LangBot before 4.10.11 Authentication Bypass via Weak Recovery Key | |
| First Time appeared |
Langbot
Langbot langbot |
|
| Weaknesses | CWE-331 | |
| CPEs | cpe:2.3:a:langbot:langbot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Langbot
Langbot langbot |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-13T10:45:36.684Z
Reserved: 2026-09-12T11:13:43.327Z
Link: CVE-2026-90562
No data.
Status : Received
Published: 2026-09-13T11:17:00.780
Modified: 2026-09-13T11:17:00.780
Link: CVE-2026-90562
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-331
Insufficient Entropy