Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-101041— Vulnerability-Lookup - Race Condition in Account Recovery Token Consumption Allows Password Takeover

Quick assessment

Affected
vulnerability-lookup vulnerability-lookup
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

漏洞描述如下: 漏洞查找(vulnerability-lookup)Web 应用的账户恢复(密码重置)功能中存在一个“检查时到使用时”(TOCTOU)竞态条件漏洞,该漏洞出现在一次性恢复令牌的使用过程中。原始实现在验证令牌 nonce 与存储的摘要是否匹配时,以及随后消耗(清除)令牌的操作,分别通过独立的数据库操作执行。因此,两个并发的 HTTP 请求如果携带相同的、有效的恢复令牌,可能在任一事务提交之前都通过验证检查,从而导致两个请求都能为同一目标账户设置各自的密码。最后提交的事务会覆盖先前的事务,使得拥有有效恢

CVSS 6.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-101041

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Vulnerability-Lookup - Race Condition in Account Recovery Token Consumption Allows Password Takeover
Source: CVE Program / CVE List V5
Vulnerability Description
The account recovery (password reset) functionality in the vulnerability-lookup web application contains a time-of-check-to-time-of-use (TOCTOU) race condition in the consumption of single-use recovery tokens. The original implementation verified the token nonce against the stored digest and then consumed (cleared) it in separate database operations. Two concurrent HTTP requests presenting the same valid recovery token could both pass the verification check before either transaction committed, allowing both to set their own password on the target account. The last transaction to commit overwrites the first, enabling an attacker who possesses a valid recovery token to replace the legitimate user's password with one of their choosing. A secondary defect in the same endpoint (confirm_account) allowed a valid recovery link to be used to set an empty or trivially short password (e.g., three characters). The view handler performed only a manual equality comparison between the two password fields and never invoked the form's validation logic, bypassing the intended minimum-length and complexity constraints. The affected component is the user account recovery endpoint (/user/confirm_account/<token>) and the associated token verification and consumption logic in the User model (website/models/user.py) and the view layer (website/web/views/user.py).
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用共享资源的并发执行不恰当同步问题(竞争条件)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
vulnerability-lookup vulnerability-lookup 0 ~ 6.2.0 -

II. Public POCs for CVE-2026-101041

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-101041

请登录查看更多情报信息。

Other References for CVE-2026-101041 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-101041

No comments yet


Leave a comment