Race Condition in Account Recovery of Vulnerability Lookup Web Application
CVE-2026-101041

6.3MEDIUM

Key Information:

Vendor
CVE Published:
27 September 2026

What is CVE-2026-101041?

A race condition in the password reset functionality of the Vulnerability Lookup Web Application allows simultaneous requests to manipulate account recovery tokens. When a valid token is presented, multiple requests can pass verification before any of them is processed, enabling an attacker with a valid token to alter a user's password. Additionally, a flaw in the password confirmation process permits the setting of weak passwords, bypassing necessary security constraints. The issue is present in the user account recovery endpoint and involves both token verification and consumption logic, compromising account integrity.

Affected Version(s)

vulnerability-lookup 0 <= 6.2.0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alexandre Dulaunoy
Cédric Bonhomme
Claude Fable 5.1
avrlab233
.