PT-2026-24792 · Git+1 · Runtipi

·

CVE-2026-31881

·

Published

2026-03-11

·

Updated

2026-03-12

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Runtipi versions prior to 4.8.0
Description Runtipi is a personal homeserver orchestrator. An unauthenticated attacker can reset the operator (admin) password when a password-reset request is active, leading to full account takeover. The API endpoint ''/api/auth/reset-password'' is exposed without authentication or authorization checks. During the 15-minute reset window, any remote user can set a new operator password and log in as administrator.
Recommendations Update to version 4.8.0 or later.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31881
GHSA-96FM-WHRC-CWG3

Affected Products

Runtipi