CVE-2026-34408
CRITICALGambio 4.0.0.0-4.9.2.0 - Weak Password Recovery Mechanism for Forgotten Password
Title source: llmDescription
An issue was discovered in Gambio 4.9.2.0 (patched in 2024-02 v1.0.0 for GX4 v4.0.0.0 to v4.9.2.0). The password reset function can be bypassed to set arbitrary passwords for arbitrary accounts if the ID is known.
Scores
CVSS v3
9.1
EPSS
0.0026
EPSS Percentile
16.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-640
Status
published
Published
May 05, 2026
Tracked Since
May 05, 2026