Vendor
An authorization bypass vulnerability in Crawlab (CVE-2026-75103) allows authenticated users to reset the passwords of any account, enabling administrator takeover and subsequent arbitrary code execution.