PT-2026-96298 · Unknown · Gladys Assistant

·

CVE-2026-93340

·

Published

2026-09-21

·

Updated

2026-09-29

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Gladys Assistant versions prior to 5.1.0
Description An issue exists where unauthenticated remote attackers can obtain valid password reset tokens for any account. This occurs due to a lack of server-side validation of the client-supplied origin parameter in the forgot password endpoint. By sending a crafted request with an attacker-controlled origin, the victim receives a poisoned reset link that discloses the session token to the attacker, potentially leading to full account takeover, including administrator accounts.
Recommendations Update Gladys Assistant to version 5.1.0 or later. As a temporary mitigation, restrict access to the forgot password endpoint or avoid using the origin parameter until the update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93340

Affected Products

Gladys Assistant