Security Advisory

CVE-2026-75103

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-17 20:36:00
Last updated 2026-08-18 15:32:54
Assigner VulnCheck
CVSS score not scored
State PUBLISHED

Description

Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and change administrator credentials to achieve full account takeover and arbitrary code execution.