{"id":"CVE-2026-108109","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-108109","summary":"PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to…","details":"PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer username can guess the code without attempt limits or lockout, then read the newly set password from the HTTP response to hijack the account.","published":"2026-10-09T14:33:32.201Z","modified":"2026-10-09T14:33:32.201Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/hotspotbilling/phpnuxbill/commit/c3c2a92d468af91136d747b75142ed72f10320cc","label":"hotspotbilling/phpnuxbill@c3c2a92"},"references":[{"type":"ADVISORY","url":"https://github.com/hotspotbilling/phpnuxbill/security/advisories/GHSA-337r-rrrc-r559"},{"type":"FIX","url":"https://github.com/hotspotbilling/phpnuxbill/commit/c3c2a92d468af91136d747b75142ed72f10320cc"},{"type":"WEB","url":"https://github.com/hotspotbilling/phpnuxbill/blob/2025.3.13/system/controllers/forgot.php#L41"},{"type":"WEB","url":"https://github.com/hotspotbilling/phpnuxbill"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/phpnuxbill-through-2025.3.20-account-takeover-via-brute-forceable-password-reset-code"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-10-09T14:33:32.201Z"}}