Unknown · Gladys Assistant · CVE-2026-93340
**Name of the Vulnerable Software and Affected Versions**
Gladys Assistant versions prior to 5.1.0
**Description**
An issue exists where unauthenticated remote attackers can obtain valid password reset tokens for any account. This occurs due to a lack of server-side validation of the client-supplied `origin` parameter in the `forgot password` endpoint. By sending a crafted request with an attacker-controlled origin, the victim receives a poisoned reset link that discloses the session token to the attacker, potentially leading to full account takeover, including administrator accounts.
**Recommendations**
Update Gladys Assistant to version 5.1.0 or later.
As a temporary mitigation, restrict access to the `forgot password` endpoint or avoid using the `origin` parameter until the update is applied.