PT-2026-24792 · Git+1 · Runtipi

Fy0Lai

·

Published

2026-03-11

·

Updated

2026-03-12

·

CVE-2026-31881

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Runtipi versions prior to 4.8.0
Description Runtipi is a personal homeserver orchestrator. An unauthenticated attacker can reset the operator (admin) password when a password-reset request is active, leading to full account takeover. The API endpoint ''/api/auth/reset-password'' is exposed without authentication or authorization checks. During the 15-minute reset window, any remote user can set a new operator password and log in as administrator.
Recommendations Update to version 4.8.0 or later.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-31881
GHSA-96FM-WHRC-CWG3

Affected Products

Runtipi