CVE-2026-75103
Received Received - Intake

Crawlab Authenticated Password Reset Vulnerability Leading to Account Takeover

Vulnerability report for CVE-2026-75103, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-17

Last updated on: 2026-08-17

Assigner: VulnCheck

Description

Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and change administrator credentials to achieve full account takeover and arbitrary code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-17
Last Modified
2026-08-17
Generated
2026-08-18
AI Q&A
2026-08-18
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Crawlab has a vulnerability where the password-change endpoint does not verify if the user is the account owner or an administrator. This allows any logged-in user to reset passwords for any other account. Attackers can first list all users to identify targets and then change admin passwords to take over accounts and execute arbitrary code.

Detection Guidance

Check for unauthorized password changes by monitoring user account modifications. Look for repeated failed login attempts or unexpected password reset requests. Inspect logs for access to the user listing endpoint by non-admin users.

Impact Analysis

If you use Crawlab, attackers could take over any account, including admin accounts, leading to full system compromise. They could steal sensitive data, modify configurations, or run malicious code on your systems. Even non-admin accounts could be hijacked, disrupting operations.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and access control, such as GDPR (data breaches) and HIPAA (unauthorized access to health data). It undermines security controls required by these regulations, potentially leading to legal penalties and loss of trust.

Mitigation Strategies

Immediately restrict access to the password-change endpoint to administrative users only. Review and audit all user accounts for unauthorized changes. Update Crawlab to the latest patched version if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75103. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart