PT-2026-48717 · Penguinmod · Penguinmod-Backendapi

CVE-2026-47181

·

Published

2026-06-11

·

Updated

2026-06-16

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PenguinMod-BackendApi versions prior to 1.0.0
Description A NoSQL injection—a method of attacking non-relational databases by manipulating queries—exists in the password reset endpoint. This allows an authenticated user with a registered account and a valid password reset token for their own account to change the password of any other account, resulting in full account takeover.
Recommendations Update to version 1.0.0.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47181

Affected Products

Penguinmod-Backendapi