LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-75103

Published
CVSS8.8
Severityhigh
WeaknessCWE-639
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and change administrator credentials to achieve full account takeover and arbitrary code execution.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-75103

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-75103.