CVE-2026-34408

An issue was discovered in Gambio 4.9.2.0 (patched in 2024-02 v1.0.0 for GX4 v4.0.0.0 to v4.9.2.0). The password reset function can be bypassed to set arbitrary passwords for arbitrary accounts if the ID is known.
Configurations

No configuration.

History

06 May 2026, 18:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
CWE CWE-640

05 May 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-05 14:16

Updated : 2026-05-06 18:16


NVD link : CVE-2026-34408

Mitre link : CVE-2026-34408

CVE.ORG link : CVE-2026-34408


JSON object : View

Products Affected

No product.

CWE
CWE-640

Weak Password Recovery Mechanism for Forgotten Password