CVE 9.8 CRITICAL

Known affected by Account Takeover via Password Reset Token Leakage_CVE-2026-26273

9.8 / 10
CRITICAL
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Known is a social publishing platform. Prior to 1.6.3, a Critical Broken Authentication vulnerability exists in Known 1.6.2 and earlier. The application leaks the password reset token within a hidden HTML input field on the password reset page. This allows any unauthenticated attacker to retrieve the reset token for any user by simply querying the user's email, leading to full Account Takeover (ATO) without requiring access to the victim's email inbox. This vulnerability is fixed in 1.6.3.

AI Analysis

Critical Broken Authentication vulnerability in Known social publishing platform, allowing unauthenticated attackers to retrieve password reset tokens and take over user accounts.

Basic Information

ID CVE-2026-26273
Source GitHub_M
Published Feb 13, 2026 at 21:45

Affected Product

Vendor idno
Product known
Version < 1.6.3
Affected Versions idno known < 1.6.3

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor idno
Product Known
Version < 1.6.3

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.