Race Condition in Account Recovery of Vulnerability Lookup Web Application
CVE-2026-101041
6.3MEDIUM
What is CVE-2026-101041?
A race condition in the password reset functionality of the Vulnerability Lookup Web Application allows simultaneous requests to manipulate account recovery tokens. When a valid token is presented, multiple requests can pass verification before any of them is processed, enabling an attacker with a valid token to alter a user's password. Additionally, a flaw in the password confirmation process permits the setting of weak passwords, bypassing necessary security constraints. The issue is present in the user account recovery endpoint and involves both token verification and consumption logic, compromising account integrity.
Affected Version(s)
vulnerability-lookup 0 <= 6.2.0
References
CVSS V4
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Alexandre Dulaunoy
Cédric Bonhomme
Claude Fable 5.1
avrlab233
