CVE-2026-19965 (GCVE-0-2026-19965)
Vulnerability from cvelistv5
Published
2026-08-17 00:00
Modified
2026-08-19 14:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the function requestPasswordResetToken of the file automad/src/server/Controllers/API/UserController.php of the component Password Reset Endpoint. This manipulation of the argument name-or-email causes observable response discrepancy. The attack can be initiated remotely. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.0.0-beta.33 is able to resolve this issue. Patch name: eac0b05dafdb0ddf8b9139dad8929aaba86568ca. You should upgrade the affected component.
References
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| n/a | automad |
Version: 2.0.0-beta.0 Version: 2.0.0-beta.1 Version: 2.0.0-beta.2 Version: 2.0.0-beta.3 Version: 2.0.0-beta.4 Version: 2.0.0-beta.5 Version: 2.0.0-beta.6 Version: 2.0.0-beta.7 Version: 2.0.0-beta.8 Version: 2.0.0-beta.9 Version: 2.0.0-beta.10 Version: 2.0.0-beta.11 Version: 2.0.0-beta.12 Version: 2.0.0-beta.13 Version: 2.0.0-beta.14 Version: 2.0.0-beta.15 Version: 2.0.0-beta.16 Version: 2.0.0-beta.17 Version: 2.0.0-beta.18 Version: 2.0.0-beta.19 Version: 2.0.0-beta.20 Version: 2.0.0-beta.21 Version: 2.0.0-beta.22 Version: 2.0.0-beta.23 Version: 2.0.0-beta.24 Version: 2.0.0-beta.25 Version: 2.0.0-beta.26 Version: 2.0.0-beta.27 Version: 2.0.0-beta.28 Version: 2.0.0-beta.29 Version: 2.0.0-beta.30 Version: 2.0.0-beta.31 Version: 2.0.0-beta.32 cpe:2.3:a:automad:automad:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-19965",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-19T14:46:43.750226Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T14:46:51.376Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://vuldb.com/submit/873022"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:automad:automad:*:*:*:*:*:*:*:*"
],
"modules": [
"Password Reset Endpoint"
],
"product": "automad",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "2.0.0-beta.0"
},
{
"status": "affected",
"version": "2.0.0-beta.1"
},
{
"status": "affected",
"version": "2.0.0-beta.2"
},
{
"status": "affected",
"version": "2.0.0-beta.3"
},
{
"status": "affected",
"version": "2.0.0-beta.4"
},
{
"status": "affected",
"version": "2.0.0-beta.5"
},
{
"status": "affected",
"version": "2.0.0-beta.6"
},
{
"status": "affected",
"version": "2.0.0-beta.7"
},
{
"status": "affected",
"version": "2.0.0-beta.8"
},
{
"status": "affected",
"version": "2.0.0-beta.9"
},
{
"status": "affected",
"version": "2.0.0-beta.10"
},
{
"status": "affected",
"version": "2.0.0-beta.11"
},
{
"status": "affected",
"version": "2.0.0-beta.12"
},
{
"status": "affected",
"version": "2.0.0-beta.13"
},
{
"status": "affected",
"version": "2.0.0-beta.14"
},
{
"status": "affected",
"version": "2.0.0-beta.15"
},
{
"status": "affected",
"version": "2.0.0-beta.16"
},
{
"status": "affected",
"version": "2.0.0-beta.17"
},
{
"status": "affected",
"version": "2.0.0-beta.18"
},
{
"status": "affected",
"version": "2.0.0-beta.19"
},
{
"status": "affected",
"version": "2.0.0-beta.20"
},
{
"status": "affected",
"version": "2.0.0-beta.21"
},
{
"status": "affected",
"version": "2.0.0-beta.22"
},
{
"status": "affected",
"version": "2.0.0-beta.23"
},
{
"status": "affected",
"version": "2.0.0-beta.24"
},
{
"status": "affected",
"version": "2.0.0-beta.25"
},
{
"status": "affected",
"version": "2.0.0-beta.26"
},
{
"status": "affected",
"version": "2.0.0-beta.27"
},
{
"status": "affected",
"version": "2.0.0-beta.28"
},
{
"status": "affected",
"version": "2.0.0-beta.29"
},
{
"status": "affected",
"version": "2.0.0-beta.30"
},
{
"status": "affected",
"version": "2.0.0-beta.31"
},
{
"status": "affected",
"version": "2.0.0-beta.32"
},
{
"status": "unaffected",
"version": "2.0.0-beta.33"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "4m3rr0r (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the function requestPasswordResetToken of the file automad/src/server/Controllers/API/UserController.php of the component Password Reset Endpoint. This manipulation of the argument name-or-email causes observable response discrepancy. The attack can be initiated remotely. The attack\u0027s complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.0.0-beta.33 is able to resolve this issue. Patch name: eac0b05dafdb0ddf8b9139dad8929aaba86568ca. You should upgrade the affected component."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 3.7,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 3.7,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 2.6,
"vectorString": "AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-204",
"description": "Observable Response Discrepancy",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-203",
"description": "Information Exposure Through Discrepancy",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T00:00:14.626Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-391142 | automad Password Reset Endpoint UserController.php requestPasswordResetToken response discrepancy",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/391142"
},
{
"name": "VDB-391142 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/391142/cti"
},
{
"name": "CVE-2026-19965 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-19965"
},
{
"name": "Submit #873022 | Automad Automad CMS 2.0.0 Information Disclosure",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/873022"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/marcantondahmen/automad/issues/191"
},
{
"tags": [
"patch"
],
"url": "https://github.com/marcantondahmen/automad/commit/eac0b05dafdb0ddf8b9139dad8929aaba86568ca"
},
{
"tags": [
"patch"
],
"url": "https://github.com/marcantondahmen/automad/releases/tag/2.0.0-beta.33"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-08-16T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-08-16T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-08-16T09:24:26.000Z",
"value": "VulDB entry last update"
}
],
"title": "automad Password Reset Endpoint UserController.php requestPasswordResetToken response discrepancy",
"x_generator": [
"VulDB PVTS v202608"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-19965",
"datePublished": "2026-08-17T00:00:14.626Z",
"dateReserved": "2026-08-16T07:19:20.973Z",
"dateUpdated": "2026-08-19T14:46:51.376Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"vulnerability-lookup:meta": {
"vulnrichment": {
"containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2026-19965\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"poc\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2026-08-19T14:46:43.750226Z\"}}}], \"references\": [{\"url\": \"https://vuldb.com/submit/873022\", \"tags\": [\"exploit\"]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2026-08-19T14:46:28.964Z\"}}], \"cna\": {\"tags\": [\"x_open-source\"], \"title\": \"automad Password Reset Endpoint UserController.php requestPasswordResetToken response discrepancy\", \"credits\": [{\"lang\": \"en\", \"type\": \"reporter\", \"value\": \"4m3rr0r (VulDB User)\"}], \"metrics\": [{\"cvssV4_0\": {\"version\": \"4.0\", \"baseScore\": 6.3, \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P\"}}, {\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 3.7, \"baseSeverity\": \"LOW\", \"vectorString\": \"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C\"}}, {\"cvssV3_0\": {\"version\": \"3.0\", \"baseScore\": 3.7, \"baseSeverity\": \"LOW\", \"vectorString\": \"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C\"}}, {\"cvssV2_0\": {\"version\": \"2.0\", \"baseScore\": 2.6, \"vectorString\": \"AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:OF/RC:C\"}}], \"affected\": [{\"cpes\": [\"cpe:2.3:a:automad:automad:*:*:*:*:*:*:*:*\"], \"vendor\": \"n/a\", \"modules\": [\"Password Reset Endpoint\"], \"product\": \"automad\", \"versions\": [{\"status\": \"affected\", \"version\": \"2.0.0-beta.0\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.1\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.2\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.3\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.4\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.5\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.6\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.7\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.8\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.9\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.10\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.11\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.12\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.13\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.14\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.15\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.16\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.17\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.18\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.19\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.20\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.21\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.22\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.23\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.24\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.25\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.26\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.27\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.28\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.29\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.30\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.31\"}, {\"status\": \"affected\", \"version\": \"2.0.0-beta.32\"}, {\"status\": \"unaffected\", \"version\": \"2.0.0-beta.33\"}]}], \"timeline\": [{\"lang\": \"en\", \"time\": \"2026-08-16T00:00:00.000Z\", \"value\": \"Advisory disclosed\"}, {\"lang\": \"en\", \"time\": \"2026-08-16T02:00:00.000Z\", \"value\": \"VulDB entry created\"}, {\"lang\": \"en\", \"time\": \"2026-08-16T09:24:26.000Z\", \"value\": \"VulDB entry last update\"}], \"references\": [{\"url\": \"https://vuldb.com/vuln/391142\", \"name\": \"VDB-391142 | automad Password Reset Endpoint UserController.php requestPasswordResetToken response discrepancy\", \"tags\": [\"vdb-entry\", \"technical-description\"]}, {\"url\": \"https://vuldb.com/vuln/391142/cti\", \"name\": \"VDB-391142 | CTI Indicators (IOB, IOC, TTP, IOA)\", \"tags\": [\"signature\", \"permissions-required\"]}, {\"url\": \"https://vuldb.com/cve/CVE-2026-19965\", \"name\": \"CVE-2026-19965 | CVE Analysis and Report\", \"tags\": [\"third-party-advisory\"]}, {\"url\": \"https://vuldb.com/submit/873022\", \"name\": \"Submit #873022 | Automad Automad CMS 2.0.0 Information Disclosure\", \"tags\": [\"third-party-advisory\"]}, {\"url\": \"https://github.com/marcantondahmen/automad/issues/191\", \"tags\": [\"exploit\", \"issue-tracking\"]}, {\"url\": \"https://github.com/marcantondahmen/automad/commit/eac0b05dafdb0ddf8b9139dad8929aaba86568ca\", \"tags\": [\"patch\"]}, {\"url\": \"https://github.com/marcantondahmen/automad/releases/tag/2.0.0-beta.33\", \"tags\": [\"patch\"]}], \"x_generator\": [\"VulDB PVTS v202608\"], \"descriptions\": [{\"lang\": \"en\", \"value\": \"A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the function requestPasswordResetToken of the file automad/src/server/Controllers/API/UserController.php of the component Password Reset Endpoint. This manipulation of the argument name-or-email causes observable response discrepancy. The attack can be initiated remotely. The attack\u0027s complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.0.0-beta.33 is able to resolve this issue. Patch name: eac0b05dafdb0ddf8b9139dad8929aaba86568ca. You should upgrade the affected component.\"}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-204\", \"description\": \"Observable Response Discrepancy\"}]}, {\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-203\", \"description\": \"Information Exposure Through Discrepancy\"}]}], \"providerMetadata\": {\"orgId\": \"1af790b2-7ee1-4545-860a-a788eba489b5\", \"shortName\": \"VulDB\", \"dateUpdated\": \"2026-08-17T00:00:14.626Z\"}}}",
"cveMetadata": "{\"cveId\": \"CVE-2026-19965\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-19T14:46:51.376Z\", \"dateReserved\": \"2026-08-16T07:19:20.973Z\", \"assignerOrgId\": \"1af790b2-7ee1-4545-860a-a788eba489b5\", \"datePublished\": \"2026-08-17T00:00:14.626Z\", \"assignerShortName\": \"VulDB\"}",
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
}
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…