Unknown · Vulnerability-Lookup · CVE-2026-101041
**Name of the Vulnerable Software and Affected Versions**
vulnerability-lookup (affected versions not specified)
**Description**
The account recovery functionality contains a time-of-check-to-time-of-use (TOCTOU) race condition—a scenario where a system checks a condition and then uses the result, but the condition changes between the check and the use—during the consumption of single-use recovery tokens. This occurs because the system verifies the token nonce and clears it in separate database operations. Consequently, two concurrent HTTP requests using the same valid token can both pass verification, allowing an attacker with a valid token to overwrite a legitimate user's password. Additionally, the `/user/confirm account/<token>` endpoint allows setting empty or trivially short passwords because the view handler performs a manual equality comparison between password fields without invoking the form's validation logic, bypassing complexity and length constraints. The issue resides in the `User` model (`website/models/user.py`) and the view layer (`website/web/views/user.py`).
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.