Password Reset Token Expiry Bypass Vulnerability in Flarum
CVE-2026-39923

9.2CRITICAL

Key Information:

Vendor

Flarum

Vendor
CVE Published:
5 August 2026

What is CVE-2026-39923?

Flarum software versions prior to 1.8.16 are susceptible to a vulnerability that allows unauthenticated attackers to exploit the password reset feature. This weakness occurs due to insufficient validation in the SavePasswordController::handle() method, where the expiry of password reset tokens is not verified. As a result, attackers can reuse expired tokens by directly submitting them to the reset processing endpoint, circumventing the intended 24-hour token lifetime and potentially gaining unauthorized access to user accounts by modifying passwords and establishing authenticated sessions.

Affected Version(s)

Flarum Framework 0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hamed Kohi
VulnCheck
.