What is CVE-2026-19965?
CVE-2026-19965 is a vulnerability found in automad up to version 2.0.0-beta.32, affecting the 'requestPasswordResetToken' function in the 'Password Reset Endpoint' component via manipulation of the 'name-or-email' argument, leading to an observable flaw. Users should urgently update to the latest version.
Azərbaycanca: CVE-2026-19965 automad platformasının (2.0.0-beta.32 versiyasına qədər) 'Password Reset Endpoint' komponentindəki `requestPasswordResetToken` funksiyasında 'name-or-email' arqumentinin manipulyasiyası nəticəsində yaranmış bir zəiflikdir. Bu qüsur müşahidə edilə bilən (observable) bir zəifliyə səbəb olur. İstifadəçilər təcili olaraq platformanı ən son versiyaya yeniləməlidir.
FAQ2
Which versions of the automad platform are affected by CVE-2026-19965?
The vulnerability affects automad up to version 2.0.0-beta.32.
Which function in automad's 'Password Reset Endpoint' is subject to the manipulation mentioned in CVE-2026-19965?
The 'requestPasswordResetToken' function is subject to manipulation of the 'name-or-email' argument, leading to an observable flaw.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.