Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-90562

Gravedad CVSS v4.0:
CRÍTICA
Tipo:
CWE-331 Entropía insuficiente
Fecha de publicación:
13/09/2026
Última modificación:
23/09/2026

Descripción

*** Pendiente de traducción *** LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access.