Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Pulatjonov Jasurbek

#43176of 57,416
6.8Total CVSS
Vulnerabilities · 1
PT-2026-96298
6.8
2026-09-21
Unknown · Gladys Assistant · CVE-2026-93340
**Name of the Vulnerable Software and Affected Versions** Gladys Assistant versions prior to 5.1.0 **Description** An issue exists where unauthenticated remote attackers can obtain valid password reset tokens for any account. This occurs due to a lack of server-side validation of the client-supplied `origin` parameter in the `forgot password` endpoint. By sending a crafted request with an attacker-controlled origin, the victim receives a poisoned reset link that discloses the session token to the attacker, potentially leading to full account takeover, including administrator accounts. **Recommendations** Update Gladys Assistant to version 5.1.0 or later. As a temporary mitigation, restrict access to the `forgot password` endpoint or avoid using the `origin` parameter until the update is applied.