Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105131— mayswind ezBookkeeping 1.2.0 before 2.0.1 Privilege Escalation via Token Refresh Endpoint

Quick assessment

Affected
mayswind ezBookkeeping
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

ezBookkeeping 1.2.0 至 2.0.1 版本(不含 2.0.1)存在一个权限提升漏洞。攻击者持有 API 令牌即可通过 /api/v1/tokens/refresh.json 接口获取完整的会话令牌。由于 TokenRefreshHandler 从不检查令牌类型,攻击者可以将短期的或受 IP 限制的 API 令牌交换为有效期为 30 天的常规会话令牌,从而绕过 API 令牌的过期机制和允许列表(白名单)限制。

CVSS 5.4 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105131

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
mayswind ezBookkeeping 1.2.0 before 2.0.1 Privilege Escalation via Token Refresh Endpoint
Source: CVE Program / CVE List V5
Vulnerability Description
ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to obtain a full session token via /api/v1/tokens/refresh.json. Because TokenRefreshHandler never checks token type, attackers can exchange short-lived or IP-restricted API tokens for 30-day normal session tokens that bypass API token expiry and allowlists.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
mayswind ezBookkeeping 1.2.0 ~ 2.0.1 -

II. Public POCs for CVE-2026-105131

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105131

请登录查看更多情报信息。

Other References for CVE-2026-105131 (6)

IV. Related Vulnerabilities

V. Comments for CVE-2026-105131

No comments yet


Leave a comment