CVE-2026-6285
Deferred Deferred - Pending Action

Weak Password Recovery in LIBRID/LIBREF

Vulnerability report for CVE-2026-6285, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: Computer Emergency Response Team of the Republic of Turkey

Description

Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026.Β NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-10
AI Q&A
2026-09-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ankaref_innovation_and_technology_inc librid *\start_including=2.01.0.2183;end_including=10092026

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-640 The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a weak password recovery mechanism in Ankaref Innovation and Technology Inc.'s LIBRID/LIBREF software. It allows attackers to exploit the password recovery process, potentially gaining unauthorized access to user accounts.

Impact Analysis

If you use LIBRID/LIBREF versions between 2.01.0.2183 and 10092026, an attacker could exploit this flaw to reset passwords without proper validation, leading to unauthorized account access and potential data breaches.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements under GDPR and HIPAA. Organizations using affected software may face compliance violations, legal penalties, and reputational damage.

Mitigation Strategies

Immediately update LIBRID/LIBREF to the latest version beyond 10092026. If no update is available, consider discontinuing use of the affected software. Implement strong password recovery mechanisms and monitor for unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-6285. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart