CVE-2026-90562
Gravedad CVSS v4.0:
CRÍTICA
Tipo:
CWE-331
Entropía insuficiente
Fecha de publicación:
13/09/2026
Última modificación:
23/09/2026
Descripción
*** Pendiente de traducción *** LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access.
Impacto
Puntuación base 4.0
9.20
Gravedad 4.0
CRÍTICA
Puntuación base 3.x
8.10
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://github.com/langbot-app/LangBot
- https://github.com/langbot-app/LangBot/blob/v4.10.2/src/langbot/pkg/api/http/controller/groups/user.py
- https://github.com/langbot-app/LangBot/blob/v4.10.2/src/langbot/pkg/core/stages/genkeys.py
- https://github.com/langbot-app/LangBot/commit/267232c24f93c515d6fd3f7f81c0676066ab1ab8
- https://github.com/langbot-app/LangBot/issues/2392
- https://www.vulncheck.com/advisories/langbot-before-4.10.11-authentication-bypass-via-weak-recovery-key
- https://github.com/langbot-app/LangBot/issues/2392


