Description
Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date header, precompute candidate tokens within a narrow time window, and probe them against the passrecover authentication endpoint to reset any account password including administrators.
Published: 2026-09-18
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Password Reset
Action: Immediate Patch
AI Analysis

Impact

A weak pseudo‑random number generator (CWE-338) is used to create password‑recovery tokens in Cotonti. The tokens are derived from md5(microtime()), producing a predictable set of roughly one million possibilities each second. An unauthenticated attacker can read the server Date header, estimate the current time, pre‑compute a list of likely tokens, and query the password‑recovery endpoint. When a token matches, the application allows the attacker to reset any account password, including that of administrators. The flaw thus delivers a remote password‑reset exploit that compromises account confidentiality, integrity, and the ability to impersonate privileged users.

Affected Systems

The vulnerability affects Cotonti versions up to 1.0.0, specifically the users.passrecover.php module in the 1.0.0 release and earlier builds. The vendor is Cotonti and the affected product is Cotonti.

Risk and Exploitability

The vulnerability has a CVSS base score of 9.2, indicating critical severity. The EPSS score of less than 1% suggests that exploitation probability is currently low, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the described pre‑computation technique can be performed within a narrow time window, making it a realistic threat for attackers with network access. The attack vector is effectively an unauthenticated network attack that requires the ability to read HTTP headers and probe the password‑recovery service.

Generated by OpenCVE AI on September 19, 2026 at 17:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the fix from the Cotonti pull request that replaces md5(microtime()) with a cryptographically secure random generator for password‑recovery tokens.
  • If an immediate upgrade is impossible, temporarily disable the password‑recovery feature or restrict its use to trusted administrators only.
  • After applying the patch, consider enforcing multi‑factor authentication for all password reset requests to further harden account security.

Generated by OpenCVE AI on September 19, 2026 at 17:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Cotonti cotonti
Vendors & Products Cotonti cotonti

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date header, precompute candidate tokens within a narrow time window, and probe them against the passrecover authentication endpoint to reset any account password including administrators.
Title Cotonti through 1.0.0 Predictable Password Recovery Token via Weak PRNG
First Time appeared Cotonti
Cotonti cotonti Siena
Weaknesses CWE-338
CPEs cpe:2.3:a:cotonti:cotonti_siena:*:*:*:*:*:*:*:*
Vendors & Products Cotonti
Cotonti cotonti Siena
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Cotonti Cotonti Cotonti Siena
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:23:16.939Z

Reserved: 2026-09-18T19:39:36.206Z

Link: CVE-2026-93868

cve-icon Vulnrichment

Updated: 2026-09-18T20:20:15.427Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T20:17:34.633

Modified: 2026-09-22T20:53:07.383

Link: CVE-2026-93868

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:00:12Z

Weaknesses
  • CWE-338

    Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)