Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 04 Oct 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to obtain a full session token via /api/v1/tokens/refresh.json. Because TokenRefreshHandler never checks token type, attackers can exchange short-lived or IP-restricted API tokens for 30-day normal session tokens that bypass API token expiry and allowlists. | |
| Title | mayswind ezBookkeeping 1.2.0 before 2.0.1 Privilege Escalation via Token Refresh Endpoint | |
| First Time appeared |
Mayswind
Mayswind ezbookkeeping |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:mayswind:ezbookkeeping:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mayswind
Mayswind ezbookkeeping |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-04T01:20:29.985Z
Reserved: 2026-10-03T12:05:26.756Z
Link: CVE-2026-105131
No data.
No data.
No data.
OpenCVE Enrichment
No data.
-
CWE-863
Incorrect Authorization