Account Takeover Vulnerability in IDURAR ERP CRM by IDURAR
CVE-2026-81031
8.6HIGH
What is CVE-2026-81031?
The IDURAR ERP CRM contains a critical flaw where the password update mechanism allows an authenticated administrator to change the password of any other administrator account without proper verification. This vulnerability arises because the update process uses an identifier from the URL path, which is not authenticated against the requesting user. As a result, an attacker with valid administrator access can exploit this weakness to set a new password for another administrator account, effectively gaining unauthorized access. This issue highlights the importance of validating user permissions against the identifiers being manipulated during critical processes such as password updates.
Affected Version(s)
idurar-erp-crm 0 <= 4.1.1
