<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cve-2026-39923 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-39923/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 05 Aug 2026 17:20:30 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-39923/feed.xml" rel="self" type="application/rss+xml"/><item><title>Password Reset Token Expiry Bypass in Flarum</title><link>https://feed.craftedsignal.io/briefs/2026-08-flarum-token-bypass/</link><pubDate>Wed, 05 Aug 2026 17:20:30 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-flarum-token-bypass/</guid><description>Flarum versions prior to 1.8.16 are vulnerable to an unauthenticated password reset token expiry bypass, allowing attackers to reuse expired tokens to gain unauthorized account access.</description><content:encoded>&lt;p>Flarum versions prior to 1.8.16 contain a security flaw in the password reset mechanism. The vulnerability exists within the SavePasswordController::handle() method, which fails to perform server-side validation of token expiration during the processing phase of a password reset.&lt;/p>
&lt;p>Although the platform enforces a 24-hour lifetime for password reset tokens during the initial form rendering process, this check is not re-validated when the submission is processed. Consequently, an unauthenticated attacker can capture or brute-force expired password reset tokens and submit them directly to the reset processing endpoint. Successful exploitation allows the attacker to reset any user account password, resulting in full account takeover and unauthorized authenticated access to the application. This vulnerability presents a high risk for organizations using Flarum for forum management or community hosting.&lt;/p>
</content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>account-takeover</category><category>cve-2026-39923</category></item></channel></rss>