CVE-2026-34408

An issue was discovered in Gambio 4.9.2.0 (patched in 2024-02 v1.0.0 for GX4 v4.0.0.0 to v4.9.2.0). The password reset function can be bypassed to set arbitrary passwords for arbitrary accounts if the ID is known.
Configurations

No configuration.

History

No history.

Information

Published : 2026-05-05 14:16

Updated : 2026-06-17 10:39


NVD link : CVE-2026-34408

Mitre link : CVE-2026-34408

CVE.ORG link : CVE-2026-34408


JSON object : View

Products Affected

No product.

CWE
CWE-640

Weak Password Recovery Mechanism for Forgotten Password