CVE-2026-105131
Received Received - Intake

Privilege Escalation in ezBookkeeping via Token Refresh Handler

Vulnerability report for CVE-2026-105131, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulnCheck

Description

ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to obtain a full session token via /api/v1/tokens/refresh.json. Because TokenRefreshHandler never checks token type, attackers can exchange short-lived or IP-restricted API tokens for 30-day normal session tokens that bypass API token expiry and allowlists.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
mayswind ezbookkeeping to 2.0.1 (exc)
mayswind ezbookkeeping 2.0.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a privilege escalation flaw in ezBookkeeping versions 1.2.0 to 2.0.0. It allows attackers with an API token to exchange it for a full 30-day session token via the /api/v1/tokens/refresh.json endpoint. The issue occurs because the TokenRefreshHandler does not validate token types, enabling unauthorized conversion of API tokens into session tokens that bypass expiry and IP allowlists.

Detection Guidance

To detect this vulnerability, check if your ezBookkeeping instance is running versions 1.2.0 to 2.0.0. Inspect API logs for unusual token refresh requests to /api/v1/tokens/refresh.json. Look for tokens being upgraded from API tokens to session tokens without proper validation.

Impact Analysis

An attacker could exploit this to gain unauthorized access to sensitive data and functions. They could bypass API token restrictions, maintain long-term access (up to 30 days or longer due to integer overflow), and perform actions like viewing user profiles or modifying settings. This is especially risky if API tokens are leaked or compromised.

Compliance Impact

This vulnerability could lead to unauthorized data access, violating principles of least privilege and data protection. For GDPR, it risks unauthorized processing of personal data. For HIPAA, it may expose protected health information. Compliance failures could result in legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Upgrade to ezBookkeeping version 2.0.1 or later immediately. Review and revoke all existing API tokens. Ensure the /api/v1/tokens/refresh.json endpoint is not accessible or properly restricted. Monitor for unauthorized session token creation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105131. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart