CVE-2026-39923CWE-324

CVE-2026-39923

High · published August 5, 2026

CVSS v3.1
8.1
EPSS
0%
Percentile
17.6
In the wild
Unconfirmed
What it is

Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reuse expired password reset tokens by submitting them directly to the reset processing endpoint. The SavePasswordController::handle() method calls PasswordToken::findOrFail() without performing any expiry validation, allowing attackers to bypass the 24-hour token lifetime enforced only during form rendering and change any account's password to gain an authenticated session.

The record
Technical detail
CVSS v3.1
8.1 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00260 · 17.6th percentile
Weakness
CWE-324 · Use of a Key Past its Expiration Date
Published
2026-08-05T20:16Z
References (4)
EPSS history
Timeline
  • 05 AUG 14:38Z
    Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset
    cvelistv5