PT-2026-33787 · Openaev · Openaev

Published

2026-04-20

·

Updated

2026-04-30

·

CVE-2026-24467

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenAEV versions 1.0.0 through 2.0.12
Description The password reset implementation contains security weaknesses that allow for reliable account takeover. Password reset tokens do not expire and remain valid indefinitely, even after new tokens are issued. Additionally, these tokens are only 8 digits long. An unauthenticated remote attacker can mass-generate valid tokens and use brute-force methods to guess a valid token, enabling them to reset any registered user's password without knowing the original password or requiring a configured email service. This can lead to full platform compromise, allowing access to sensitive data and the ability to modify payloads executed by deployed agents to compromise hosts.
Recommendations Upgrade to version 2.0.13.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-24467

Affected Products

Openaev