CVE-2026-93340
Received Received - Intake

Password Reset Link Poisoning in Gladys Assistant

Vulnerability report for CVE-2026-93340, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-21

Last updated on: 2026-09-21

Assigner: VulnCheck

Description

Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting the client-supplied origin parameter in the forgot_password endpoint without server-side validation. Attackers can send a crafted request specifying an attacker-controlled origin, causing the victim to receive a poisoned reset link that discloses the session token to the attacker, enabling full account takeover including administrator accounts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-21
Last Modified
2026-09-21
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gladys_assistant gladys_assistant to 5.1.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-640 The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Gladys Assistant before version 5.1.0 has a vulnerability where attackers can trick the system into sending password reset links to an attacker-controlled server. By manipulating the origin parameter in the password reset request, an attacker can obtain valid reset tokens for any account without authentication. When a victim uses this poisoned link, their session token is exposed to the attacker, allowing full account takeover including administrator accounts.

Detection Guidance

Detecting this vulnerability requires checking if Gladys Assistant versions before 5.1.0 are running and if the forgot_password endpoint accepts client-supplied origin parameters without validation. Inspect server logs for reset link requests with unusual origins or tokens. No specific commands are provided in the context.

Impact Analysis

If you use Gladys Assistant before version 5.1.0, an attacker could gain control of your account, access sensitive data, or perform actions on your behalf. Administrator accounts are particularly at risk, which could lead to complete system compromise. The attack requires no authentication and can be executed remotely.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Organizations using vulnerable versions may face compliance violations, legal penalties, and reputational damage due to potential data breaches.

Mitigation Strategies

Upgrade Gladys Assistant to version 5.1.0 or later immediately. Ensure the forgot_password endpoint validates server-side origins and does not accept client-supplied parameters. Review and revoke any potentially compromised reset tokens.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93340. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart