CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. See the original NVD description below for full technical details.
CVE
CVE-2026-48902
Severity
CRITICAL
CVSS
9.8
EPSS
0.25%
Original NVD Description
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
Related CVEs
Other vulnerabilities affecting the same vendor(s)