What is CVE-2026-39923?
Flarum versions before 1.8.16 contain a password reset token expiry bypass vulnerability. This allows unauthenticated attackers to reuse expired password reset tokens by submitting them directly to the `SavePasswordController::handle()` method. Affected users should immediately upgrade to version 1.8.16 or later.
Azərbaycanca: Flarum-un 1.8.16-dan əvvəlki versiyalarında şifrə sıfırlama tokeninin müddətini keçmə (expiry bypass) zəifliyi aşkar edilib. Bu boşluq autentifikasiya olunmamış hücumçulara müddəti bitmiş şifrə sıfırlama tokenlərini birbaşa `SavePasswordController::handle()` metoduna göndərərək təkrar istifadə etməyə imkan verir. Flarum istifadəçiləri dərhal 1.8.16 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of Flarum are affected by the CVE-2026-39923 password reset token expiry bypass vulnerability?
All Flarum versions before 1.8.16 are affected by this vulnerability.
What does the CVE-2026-39923 vulnerability allow an unauthenticated attacker to do?
This vulnerability allows an unauthenticated attacker to reuse expired password reset tokens by submitting them directly to the `SavePasswordController::handle()` method.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.