Weak Password Recovery Mechanism in LangBot by LangBot App
CVE-2026-90562
9.2CRITICAL
What is CVE-2026-90562?
A vulnerability exists in LangBot prior to version 4.10.11, where the application generates password recovery keys with insufficient entropy (only 24 bits). Additionally, the absence of rate limiting on the unauthenticated reset-password endpoint allows remote attackers to exploit this weakness. By leveraging knowledge of the administrator's email, attackers can execute concurrent requests to reset the admin password, leading to potential unauthorized access to the account.
Affected Version(s)
LangBot 4.0.8.1 < 4.10.11
