Password Reset Link Poisoning Vulnerability in Gladys Assistant by Gladys
CVE-2026-93340

7.4HIGH

Key Information:

Vendor
CVE Published:
21 September 2026

What is CVE-2026-93340?

Gladys Assistant prior to version 5.1.0 is susceptible to a password reset link poisoning vulnerability. This flaw allows unauthenticated attackers to exploit the client-supplied origin parameter in the forgot_password endpoint to generate valid password reset tokens. By manipulating this parameter, an attacker can craft a request that leads to the victim receiving a malicious reset link. This link can disclose the session token to the attacker, resulting in potential full account takeover, including access to administrator accounts. Users should update to version 5.1.0 or later to mitigate this risk.

Affected Version(s)

Gladys Assistant 0 < 5.1.0

References

CVSS V4

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pulatjonov Jasurbek
VulnCheck
.