HIGH 8.7 NVD
CVE-2026-75103
Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password.
Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and change administrator credentials to achieve full account takeover and arbitrary code execution.
References
- https://github.com/crawlab-team/crawlab
- https://github.com/crawlab-team/crawlab/blob/main/core/controllers/user_v2.go
- https://github.com/crawlab-team/crawlab/issues/1623
- https://www.vulncheck.com/advisories/crawlab-missing-authorization-on-password-change-endp
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-08-17 via NVD.
vulnfeed aggregates 11051 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.