Feed/CVE-2026-1670
CVE-2026-1670CRITICALCVSS 9.8

CVE-2026-1670

Published Feb 17, 2026·Updated Jun 17, 2026

NVD Description

The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery email address.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free