CVE-2026-90562

Source
https://cve.org/CVERecord?id=CVE-2026-90562
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90562.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90562
Published
2026-09-13T10:45:36Z
Modified
2026-09-18T03:31:03Z
Severity
  • 9.2 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
LangBot before 4.10.11 Authentication Bypass via Weak Recovery Key
Details

LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-331"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90562.json"
}
References

Affected packages

Git / github.com/langbot-app/langbot

Affected ranges

Type
GIT
Repo
https://github.com/langbot-app/langbot
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "4.0.8.1"
        },
        {
            "fixed": "4.10.11"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v.*
v.4.4.2b1
v4.*
v4.0.8.1
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v4.10.0
v4.10.0-beta.2
v4.10.0-beta.3
v4.10.1
v4.10.10
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.10.6
v4.10.7
v4.10.8
v4.10.9
v4.2.0
v4.2.1
v4.2.2
v4.3.0
v4.3.0.beta2
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
v4.3.7b1
v4.3.8
v4.3.9
v4.4.0
v4.4.1
v4.4.2b1
v4.5.0
v4.5.1b1
v4.5.1b2
v4.5.1b3
v4.5.3
v4.5.4
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.7.0
v4.7.1
v4.7.2
v4.8.0
v4.8.1
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v4.9.6
v4.9.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90562.json"