CVE-2026-16751
Deferred Deferred - Pending Action

Authorization Bypass in Ente Museum Server Emergency Recovery

Vulnerability report for CVE-2026-16751, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-29

Last updated on: 2026-07-30

Assigner: CERT/CC

Description

Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum Server allows an authenticated attacker configured as a victim's emergency contact to bypass the configured recovery waiting period and take over the victim's account via a crafted `approve-recovery` API request.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-29
Last Modified
2026-07-30
Generated
2026-08-19
AI Q&A
2026-07-30
EPSS Evaluated
2026-08-18
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ente_technologies ente_museum_server *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authorization bypass in the emergency recovery approval component of Ente Technologies Ente Museum Server. An authenticated attacker who is configured as a victim's emergency contact can bypass the recovery waiting period and take over the victim's account by sending a specially crafted approve-recovery API request.

Impact Analysis

If you are an Ente Museum Server user with an emergency contact configured, an attacker who compromises that contact's account could take over your account. This could lead to unauthorized access to your data, loss of control over your account, and potential exposure of sensitive information.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, which may violate GDPR's data protection principles or HIPAA's security requirements. Organizations using Ente Museum Server may face compliance risks if this flaw is exploited, potentially resulting in data breaches and regulatory penalties.

Mitigation Strategies

Disable or restrict emergency recovery approval functionality in Ente Museum Server until a patch is applied. Review and remove unauthorized emergency contacts for all accounts. Monitor API logs for suspicious approve-recovery requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16751. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart