目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-101041— 账号恢复令牌竞争条件导致密码劫持

一分钟漏洞结论

影响对象
vulnerability-lookup vulnerability-lookup
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

漏洞描述如下: 漏洞查找(vulnerability-lookup)Web 应用的账户恢复(密码重置)功能中存在一个“检查时到使用时”(TOCTOU)竞态条件漏洞,该漏洞出现在一次性恢复令牌的使用过程中。原始实现在验证令牌 nonce 与存储的摘要是否匹配时,以及随后消耗(清除)令牌的操作,分别通过独立的数据库操作执行。因此,两个并发的 HTTP 请求如果携带相同的、有效的恢复令牌,可能在任一事务提交之前都通过验证检查,从而导致两个请求都能为同一目标账户设置各自的密码。最后提交的事务会覆盖先前的事务,使得拥有有效恢

CVSS 6.3 · Medium
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-101041 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Vulnerability-Lookup - Race Condition in Account Recovery Token Consumption Allows Password Takeover
来源: CVE Program / CVE List V5
Vulnerability Description
The account recovery (password reset) functionality in the vulnerability-lookup web application contains a time-of-check-to-time-of-use (TOCTOU) race condition in the consumption of single-use recovery tokens. The original implementation verified the token nonce against the stored digest and then consumed (cleared) it in separate database operations. Two concurrent HTTP requests presenting the same valid recovery token could both pass the verification check before either transaction committed, allowing both to set their own password on the target account. The last transaction to commit overwrites the first, enabling an attacker who possesses a valid recovery token to replace the legitimate user's password with one of their choosing. A secondary defect in the same endpoint (confirm_account) allowed a valid recovery link to be used to set an empty or trivially short password (e.g., three characters). The view handler performed only a manual equality comparison between the two password fields and never invoked the form's validation logic, bypassing the intended minimum-length and complexity constraints. The affected component is the user account recovery endpoint (/user/confirm_account/<token>) and the associated token verification and consumption logic in the User model (website/models/user.py) and the view layer (website/web/views/user.py).
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
使用共享资源的并发执行不恰当同步问题(竞争条件)
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
vulnerability-lookup vulnerability-lookup 0 ~ 6.2.0 -

二、漏洞 CVE-2026-101041 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-101041 的情报信息

请登录查看更多情报信息。

CVE-2026-101041 其他参考 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-101041

暂无评论


发表评论