Privilege Escalation in ezBookkeeping by Mayswind
CVE-2026-105131

5.3MEDIUM

Key Information:

Vendor

Mayswind

Vendor
CVE Published:
4 October 2026

What is CVE-2026-105131?

ezBookkeeping versions prior to 2.0.1 contain a vulnerability that enables a privilege escalation attack via the token refresh endpoint. This flaw permits attackers with a valid API token to exploit the /api/v1/tokens/refresh.json endpoint. The TokenRefreshHandler’s lack of verification on the token type allows these attackers to convert short-lived or IP-restricted API tokens into long-lasting session tokens. Consequently, this vulnerability poses a significant security risk as it bypasses token expiry mechanisms and allowlists, potentially granting unauthorized access to sensitive user sessions.

Affected Version(s)

ezBookkeeping 1.2.0 < 2.0.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

EVIL0RD
.