PT-2026-21270 · Monica · Monica

Hungnqdz

·

Published

2026-02-20

·

Updated

2026-02-23

·

CVE-2026-26747

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Monica version 4.1.2
Description A Host Header Poisoning issue exists due to improper handling of the HTTP Host header in the file app/Providers/AppServiceProvider.php. This is combined with a default misconfiguration where app.force url is not set, defaulting to "false". The application constructs absolute URLs, including those in password reset emails, using the user-supplied Host header. This allows attackers to manipulate the password reset link sent to a victim.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-26747

Affected Products

Monica