← العودة للجدول
CVE-2026-47181
CVE-2026-47181 — PenguinMod-BackendApi is the backend api for penguinmod. Prior to version 1.0.0,
📅 2026-06-11
🟠 High 🔥 No NVD Exploit Web

📋 الوصف الكامل

PenguinMod-BackendApi is the backend api for penguinmod. Prior to version 1.0.0, a NoSQL injection vulnerability in the password reset endpoint allows any authenticated user to change the password of an account, leading to full account takeover. An attacker only needs a registered account and a valid password reset token for their own account. This issue has been patched in version 1.0.0.

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-47181

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v1.0.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←