OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-93868

HIGH · CVSS 8.1 EPSS 0.73% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The vulnerability allows unauthenticated attackers to exploit predictable password recovery tokens generated by Cotonti, enabling them to reset any user account password, including those of administrators. By leveraging the server's Date header, attackers can precompute potential tokens and systematically test them against the authentication endpoint. Organizations using Cotonti, especially those with administrative access, should prioritize patching this vulnerability to prevent unauthorized account access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-93868
Severity
HIGH
CVSS
8.1
EPSS
0.73%

Original NVD Description

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date header, precompute candidate tokens within a narrow time window, and probe them against the passrecover authentication endpoint to reset any account password including administrators.