Privilege Escalation in ezBookkeeping by Mayswind
CVE-2026-105131
5.3MEDIUM
What is CVE-2026-105131?
ezBookkeeping versions prior to 2.0.1 contain a vulnerability that enables a privilege escalation attack via the token refresh endpoint. This flaw permits attackers with a valid API token to exploit the /api/v1/tokens/refresh.json endpoint. The TokenRefreshHandler’s lack of verification on the token type allows these attackers to convert short-lived or IP-restricted API tokens into long-lasting session tokens. Consequently, this vulnerability poses a significant security risk as it bypasses token expiry mechanisms and allowlists, potentially granting unauthorized access to sensitive user sessions.
Affected Version(s)
ezBookkeeping 1.2.0 < 2.0.1
