CVE-2026-75103 - Crawlab Missing Authorization on Password Change Endpoint Allows Account Takeover
Brief
CVE ID : CVE-2026-75103
Published : Aug. 17, 2026, 8:36 p. m.
- 31 minutes ago
Description : Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and change administrator credentials to achieve full account takeover and arbitrary code execution.
Severity: 8.8
- HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
