PT-2026-99549 · Unknown · Vulnerability-Lookup

·

CVE-2026-101041

·

Published

2026-09-27

·

Updated

2026-09-29

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions vulnerability-lookup (affected versions not specified)
Description The account recovery functionality contains a time-of-check-to-time-of-use (TOCTOU) race condition—a scenario where a system checks a condition and then uses the result, but the condition changes between the check and the use—during the consumption of single-use recovery tokens. This occurs because the system verifies the token nonce and clears it in separate database operations. Consequently, two concurrent HTTP requests using the same valid token can both pass verification, allowing an attacker with a valid token to overwrite a legitimate user's password. Additionally, the /user/confirm account/<token> endpoint allows setting empty or trivially short passwords because the view handler performs a manual equality comparison between password fields without invoking the form's validation logic, bypassing complexity and length constraints. The issue resides in the User model (website/models/user.py) and the view layer (website/web/views/user.py).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Race Condition

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101041

Affected Products

Vulnerability-Lookup