PT-2026-34172 · Kovah · Linkace

Published

2026-04-21

·

Updated

2026-04-27

·

CVE-2026-40905

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions LinkAce versions prior to 2.5.4
Description An issue exists where the application improperly trusts user-controlled HTTP headers. Specifically, the application uses the X-Forwarded-Host header when generating password reset URLs. An attacker can manipulate this header during a password reset request to inject a malicious domain into the reset link sent via email. If a victim clicks this link, the password reset token is transmitted to the attacker-controlled server, allowing the attacker to capture the token and reset the victim's password, resulting in full account takeover.
Recommendations Update to version 2.5.4.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40905

Affected Products

Linkace