Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-93868: Cotonti password reset can be guessed

CVE-2026-93868 · published 10 days ago
Summary

The password reset feature in Cotonti (up to version 1.0.0) creates codes that can be guessed because they are based on the server's current time. An attacker who knows the server's clock can try a few thousand possible codes and may reset any user's password, including administrators. Update Cotonti to a newer version or apply a patch that uses a stronger random generator for reset codes.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
cotonti cotonti <= 1.0.0
Original advisory text
Cotonti through 1.0.0 Predictable Password Recovery Token via Weak PRNG
Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date header, precompute candidate tokens within a narrow time window, and probe them against the passrecover authentication endpoint to reset any account password including administrators.
Severity
9.4 Critical
CVSS 3.1: 8.1 (MITRE)
Exploitation
EPSS <1%
Type
CWE-338Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
Timeline
Published18 Sep 2026
Updated27 Sep 2026
First seen18 Sep 2026
Sources
CVE-2026-93868 · MITRE
Track software like this
Free during beta