[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#CVE-2026-39923

articleHIGH 8.1

CVE-2026-39923: Flarum Password Reset Token Expiry Bypass Vulnerability

A critical vulnerability (CVE-2026-39923, CVSS 8.1) in Flarum, a popular discussion platform, allows unauthenticated attackers to bypass the 24-hour password reset token expiry, potentially leading to unauthorized account takeovers. The vulnerability affects Flarum versions prior to 1.8.16. Organizations using Flarum should immediately upgrade to version 1.8.16 or later to mitigate this risk. Failure to do so may result in compromised user accounts and potential lateral movement within the network.

Aug 6, 20261 source