LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access. | |
| Title | LangBot before 4.10.11 Authentication Bypass via Weak Recovery Key | |
| First Time appeared |
Langbot
Langbot langbot |
|
| Weaknesses | CWE-331 | |
| CPEs | cpe:2.3:a:langbot:langbot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Langbot
Langbot langbot |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-13T10:45:36.684Z
Reserved: 2026-09-12T11:13:43.327Z
Link: CVE-2026-90562
No data.
Status : Received
Published: 2026-09-13T11:17:00.780
Modified: 2026-09-13T11:17:00.780
Link: CVE-2026-90562
No data.
OpenCVE Enrichment
No data.
Weaknesses