CVE-2026-108109
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-108109, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: VulnCheck

Description

PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer username can guess the code without attempt limits or lockout, then read the newly set password from the HTTP response to hijack the account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hotspotbilling phpnuxbill 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-307 The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

PHPNuxBill through 2025.3.20 has an account takeover vulnerability in the customer password reset process. The flaw is in system/controllers/forgot.php where unauthenticated attackers can brute-force a 6-digit OTP code. If an attacker knows a customer's username, they can repeatedly guess the OTP without limits or lockouts. Once the correct code is entered, the attacker can set a new password and hijack the account by reading the response.

Detection Guidance

Detecting this vulnerability requires monitoring for repeated failed password reset attempts targeting the customer username field in system/controllers/forgot.php. Check web server logs for excessive POST requests to the forgot password endpoint with the same username and varying 6-digit otp_code values. Look for HTTP responses containing newly set passwords after successful OTP submissions.

Impact Analysis

This vulnerability allows attackers to take over customer accounts by guessing the password reset code. If you are a user of PHPNuxBill, an attacker knowing your username could reset your password, gain access to your account, and potentially steal sensitive data or perform unauthorized actions. The lack of rate limiting makes this attack feasible and dangerous.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR and HIPAA requirements for data protection and access control. Organizations using PHPNuxBill may face compliance violations, legal penalties, and reputational damage if customer data is exposed due to this flaw.

Mitigation Strategies
  • Implement rate limiting on the password reset endpoint to prevent brute-force attempts.
  • Add account lockout after a small number of failed OTP attempts (e.g., 3-5 attempts).
  • Replace the 6-digit OTP with a longer, more complex code (e.g., 8+ characters with mixed types).
  • Ensure the HTTP response does not expose the newly set password in the body or headers.
  • Upgrade PHPNuxBill to the latest patched version if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108109. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart