CVE-2026-1670

CRITICAL

Affected Products - Info Disclosure

Title source: llm

Description

The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery email address.

Scores

CVSS v3 9.8
EPSS 0.0005
EPSS Percentile 15.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-306
Status draft

Timeline

Published Feb 17, 2026
Tracked Since Feb 18, 2026