PT-2026-39211 · Sysreptor · Sysreptor

Lowaronmolnar

·

Published

2026-05-08

·

Updated

2026-05-09

·

CVE-2026-44987

CVSS v3.1

3.8

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SysReptor versions prior to 2026.29
Description Users with "User Admin" permissions can modify the email addresses of users with "Superuser" permissions. When the "Forgot Password" functionality is enabled, these users can reset Superuser passwords and authenticate, provided the Superuser does not have multi-factor authentication (MFA) enabled. This allows unauthorized access to the Django backend endpoint "/admin" or the ability to manipulate installation settings.
Recommendations Update to version 2026.29.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44987

Affected Products

Sysreptor