Latest
Alerts
Security
DevOps
Cloud
AI
Self-hosted
Linux
Networking
Search
⌘K
FR
live
CVE-2026-48710 · Kludex Starlette
CVE-2026-49869 · Kestra Kestra OSS
CVE-2026-59822 · BerriAI LiteLLM · CVSS 8.2
CVE-2026-82329 · JFrog Artifactory
home
alerts
CWE-324
weakness type
CWE-324
1
vulnerability tracked
5 August 2026
latest publication
cve
Vulnerability watch
id
vulnerability
severity
published
CVE-2026-39923
Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reuse expired password reset tokens by submitting them directly to the reset processing endpoint. The SavePasswordController::handle() method calls PasswordToken::findOrFail() without performing any expiry validation, allowing attackers to bypass the 24-hour token lifetime enforced only during form rendering and change any account's password to gain an authenticated session.
NVD analysis in progress
High
CVSS 8.1
05/08
← Back to the watch
CWE entry on mitre.org →
esc
Type at least two characters.
↑
↓
navigate
↵
open
esc
dismiss