CVE-2026-73431

EUVD-2026-57226
Vulnerability-Lookup contains an 
authentication weakness in its account activation and password-recovery 
mechanism. Activation and recovery links were generated using stateless 
signed tokens containing only the user's login. Although the token 
signature and age were validated, the application did not track whether a
 token had already been successfully used. As a result, a captured 
activation or password-recovery link remained valid for the entire 
configured TOKEN_VALIDITY_PERIOD, even after the associated password had been changed. 


An attacker who obtains a valid 
activation or recovery token could therefore replay it multiple times 
during its validity period to set a new password and repeatedly take 
control of the affected account. In addition, tokens were not bound to a
 specific purpose, allowing the same token mechanism to be used across 
activation and recovery workflows. The patch introduces purpose-bound 
tokens and a random nonce whose SHA-256 digest is stored with the user 
account. The nonce is invalidated after a successful password change, 
making tokens single-use, while issuing a new token invalidates any 
previously issued token.  The password-setting operation now explicitly consumes the token before committing the account change. 


Successful exploitation requires 
the attacker to obtain a currently valid activation or recovery link, 
but does not require knowledge of the victim's existing password or an 
authenticated session.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---