Description
A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the function requestPasswordResetToken of the file automad/src/server/Controllers/API/UserController.php of the component Password Reset Endpoint. This manipulation of the argument name-or-email causes observable response discrepancy. The attack can be initiated remotely. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.0.0-beta.33 is able to resolve this issue. Patch name: eac0b05dafdb0ddf8b9139dad8929aaba86568ca. You should upgrade the affected component.
Published: 2026-08-17
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Marcantondahmen
Marcantondahmen automad
Vendors & Products Marcantondahmen
Marcantondahmen automad

Mon, 17 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the function requestPasswordResetToken of the file automad/src/server/Controllers/API/UserController.php of the component Password Reset Endpoint. This manipulation of the argument name-or-email causes observable response discrepancy. The attack can be initiated remotely. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.0.0-beta.33 is able to resolve this issue. Patch name: eac0b05dafdb0ddf8b9139dad8929aaba86568ca. You should upgrade the affected component.
Title automad Password Reset Endpoint UserController.php requestPasswordResetToken response discrepancy
First Time appeared Automad
Automad automad
Weaknesses CWE-203
CWE-204
CPEs cpe:2.3:a:automad:automad:*:*:*:*:*:*:*:*
Vendors & Products Automad
Automad automad
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Automad Automad
Marcantondahmen Automad
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-17T00:00:14.626Z

Reserved: 2026-08-16T07:19:20.973Z

Link: CVE-2026-19965

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T00:16:27.450

Modified: 2026-08-17T00:16:27.450

Link: CVE-2026-19965

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T01:30:17Z

Weaknesses
  • CWE-203

    Observable Discrepancy

  • CWE-204

    Observable Response Discrepancy