Password Reset Vulnerability in Crawlab Affects User Security
CVE-2026-75103
8.7HIGH
What is CVE-2026-75103?
Crawlab contains a vulnerability in its password-change endpoint that fails to properly authenticate user ownership or verify administrative roles. This oversight permits any authenticated user to reset passwords for other accounts, facilitating unauthorized access. Malicious users can exploit this weakness to enumerate user accounts via the user listing endpoint. By changing administrator credentials, attackers can seize full control of accounts, potentially leading to arbitrary code execution. It is crucial to implement effective access controls and user verification to mitigate this risk.
Affected Version(s)
crawlab 0 <= 0.6.3
