← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 17, 2026 · 20:36via CVEFeed

CVE-2026-75103 - Crawlab Missing Authorization on Password Change Endpoint Allows Account Takeover

Brief

CVE ID : CVE-2026-75103

Published : Aug. 17, 2026, 8:36 p. m.

  • 31 minutes ago

Description : Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and change administrator credentials to achieve full account takeover and arbitrary code execution.

Severity: 8.8

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed