CVE-2026-34408

CRITICAL

Gambio 4.0.0.0-4.9.2.0 - Weak Password Recovery Mechanism for Forgotten Password

Title source: llm
STIX 2.1

Description

An issue was discovered in Gambio 4.9.2.0 (patched in 2024-02 v1.0.0 for GX4 v4.0.0.0 to v4.9.2.0). The password reset function can be bypassed to set arbitrary passwords for arbitrary accounts if the ID is known.

Scores

CVSS v3 9.1
EPSS 0.0026
EPSS Percentile 16.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-640
Status published
Published May 05, 2026
Tracked Since May 05, 2026