Weak Password Recovery Mechanism in LangBot by LangBot App
CVE-2026-90562

9.2CRITICAL

Key Information:

Status
Vendor
CVE Published:
13 September 2026

What is CVE-2026-90562?

A vulnerability exists in LangBot prior to version 4.10.11, where the application generates password recovery keys with insufficient entropy (only 24 bits). Additionally, the absence of rate limiting on the unauthenticated reset-password endpoint allows remote attackers to exploit this weakness. By leveraging knowledge of the administrator's email, attackers can execute concurrent requests to reset the admin password, leading to potential unauthorized access to the account.

Affected Version(s)

LangBot 4.0.8.1 < 4.10.11

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.