Password Reset Token Expiry Bypass Vulnerability in Flarum
CVE-2026-39923
9.2CRITICAL
What is CVE-2026-39923?
Flarum software versions prior to 1.8.16 are susceptible to a vulnerability that allows unauthenticated attackers to exploit the password reset feature. This weakness occurs due to insufficient validation in the SavePasswordController::handle() method, where the expiry of password reset tokens is not verified. As a result, attackers can reuse expired tokens by directly submitting them to the reset processing endpoint, circumventing the intended 24-hour token lifetime and potentially gaining unauthorized access to user accounts by modifying passwords and establishing authenticated sessions.
Affected Version(s)
Flarum Framework 0
