Password Reset Link Poisoning Vulnerability in Gladys Assistant by Gladys
CVE-2026-93340
7.4HIGH
What is CVE-2026-93340?
Gladys Assistant prior to version 5.1.0 is susceptible to a password reset link poisoning vulnerability. This flaw allows unauthenticated attackers to exploit the client-supplied origin parameter in the forgot_password endpoint to generate valid password reset tokens. By manipulating this parameter, an attacker can craft a request that leads to the victim receiving a malicious reset link. This link can disclose the session token to the attacker, resulting in potential full account takeover, including access to administrator accounts. Users should update to version 5.1.0 or later to mitigate this risk.
Affected Version(s)
Gladys Assistant 0 < 5.1.0
