CVE-2026-75103

Source
https://cve.org/CVERecord?id=CVE-2026-75103
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75103.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-75103
Published
2026-08-17T20:36:00.054Z
Modified
2026-08-20T03:30:07.971190376Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Crawlab Missing Authorization on Password Change Endpoint Allows Account Takeover
Details

Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and change administrator credentials to achieve full account takeover and arbitrary code execution.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75103.json"
}
References

Affected packages

Git / github.com/crawlab-team/crawlab

Affected ranges

Type
GIT
Repo
https://github.com/crawlab-team/crawlab
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.6.3"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v0.*
v0.1
v0.1.1
v0.2
v0.2.1
v0.2.2
v0.2.3
v0.2.4
v0.3.0
v0.3.1
v0.3.2
v0.3.3
v0.3.4
v0.3.5
v0.4.0
v0.4.1
v0.4.10
v0.4.2
v0.4.3
v0.4.4
v0.4.5
v0.4.6
v0.4.7
v0.4.8
v0.4.9
v0.5.0
v0.5.1
v0.6.0-beta.20210803
v0.6.3-dev

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75103.json"