What is CVE-2026-16751?
This vulnerability is an authorization bypass in the emergency recovery approval component of Ente Technologies Ente Museum Server. An authenticated attacker, configured as a victim's emergency contact, can bypass the recovery waiting period and take over the account via a crafted `approve-recovery` request. Users should carefully select emergency contacts and update the server to the latest patched version.
Azərbaycanca: Bu zəiflik Ente Technologies Ente Museum Server-in fövqəladə bərpa təsdiq komponentində avtorizasiyadan yan keçməyə imkan verir. Qurbanın fövqəladə əlaqə şəxsi kimi təyin edilmiş autentifikasiya olunmuş hücumçu, gözləmə müddətini keçərək `approve-recovery` sorğusu vasitəsilə hesabı ələ keçirə bilər. İstifadəçilərə fövqəladə əlaqə şəxslərini diqqətlə seçmək və serveri ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ1
How can an attacker exploiting CVE-2026-16751 take over a victim's account?
An authenticated attacker configured as the victim's emergency contact can bypass the recovery waiting period and take over the account via a crafted `approve-recovery` request.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.