CVE-2026-47181

NONE
CVSS v3
CVSS v2
0.25% EPSS (exploit probability)
CWE-20CWE

Description

PenguinMod-BackendApi is the backend api for penguinmod. Prior to version 1.0.0, a NoSQL injection vulnerability in the password reset endpoint allows any authenticated user to change the password of an account, leading to full account takeover. An attacker only needs a registered account and a valid password reset token for their own account. This issue has been patched in version 1.0.0.

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references