Description
LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access.
Published: 2026-09-13
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

LangBot versions earlier than 4.10.11 can generate password recovery keys with only 24 bits of entropy, which is far below the level required. Knowing the administrator e‑mail address, attackers can exhaust the limited keyspace by flooding the unauthenticated reset‑password endpoint, thereby bypassing authentication and gaining administrative access for the application.

Affected Systems

The vulnerability affects the LangBot application produced by langbot-app. All installations running any version earlier than 4.10.11 are potentially vulnerable, as the weak key generation is implemented in the core recovery key module and the reset endpoint lacks any form of rate limiting. Users of the latest releases to have a patched implementation.

Risk and Exploitability

The CVSS score of 9.2 classifies this flaw as critical, indicating that exploitation could lead to total compromise of the system. The EPSS score is approximately 0.00424 (~0.42%), indicating a very low overall likelihood of exploitation but does not negate the risk in targeted scenarios. The lack of rate limiting and the extremely small keyspace make this exploit highly likely in practice, even though it is not yet listed in KEV. The attack vector is inferred to be remote, leveraging the unauthenticated reset‑password API and exhaustive key guessing.

Generated by OpenCVE AI on September 15, 2026 at 17:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade LangBot to version 4.10.11 or later, limiting to the reset‑password endpoint.
  • Configure the application to limit reset‑password requests per IP or per account, preventing brute‑force exhaustion of the recovery key space.
  • Enforce the use of recovery keys with at least 128‑bit entropy or disable insecure recovery key generation entirely, and restrict exposure of administrator email addresses.

Generated by OpenCVE AI on September 15, 2026 at 17:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access.
Title LangBot before 4.10.11 Authentication Bypass via Weak Recovery Key
First Time appeared Langbot
Langbot langbot
Weaknesses CWE-331
CPEs cpe:2.3:a:langbot:langbot:*:*:*:*:*:*:*:*
Vendors & Products Langbot
Langbot langbot
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:21:47.359Z

Reserved: 2026-09-12T11:13:43.327Z

Link: CVE-2026-90562

cve-icon Vulnrichment

Updated: 2026-09-16T14:01:49.445Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T11:17:00.780

Modified: 2026-09-23T17:17:47.433

Link: CVE-2026-90562

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:15:14Z

Weaknesses