CVE-2026-53646
FOSSBilling
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when a `ClientPasswordReset` record already exists for a client (from a previous unexpired reset request), subsequent calls to the `reset_password` guest API endpoint reuse the existing token instead of generating a new one. The 15-minute validity window is anchored to the first request's `created_at` timestamp, not the time of the most recent email. An attacker who obtained the original reset link remains able to use it even after the victim requests a new reset, because the original t...
- CVSS
- 7.7
- EPSS
- 0.21% 12.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.07