An issue was discovered in Gambio 4.9.2.0 (patched in 2024-02 v1.0.0 for GX4 v4.0.0.0 to v4.9.2.0). The password reset function can be bypassed to set arbitrary passwords for arbitrary accounts if the ID is known.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 05 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gambio
Gambio gambio |
|
| Vendors & Products |
Gambio
Gambio gambio |
Tue, 05 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Password Reset Bypass in Gambio 4.9.2.0 Enables Arbitrary Password Setting | |
| Weaknesses | CWE-287 |
Tue, 05 May 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Gambio 4.9.2.0 (patched in 2024-02 v1.0.0 for GX4 v4.0.0.0 to v4.9.2.0). The password reset function can be bypassed to set arbitrary passwords for arbitrary accounts if the ID is known. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-05T13:29:49.337Z
Reserved: 2026-03-27T00:00:00.000Z
Link: CVE-2026-34408
No data.
Status : Deferred
Published: 2026-05-05T14:16:08.623
Modified: 2026-05-05T20:24:04.853
Link: CVE-2026-34408
No data.
OpenCVE Enrichment
Updated: 2026-05-05T16:00:17Z
Weaknesses