
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26273 is a Critical Broken Authentication vulnerability in the Known social publishing platform (versions ≤ 1.6.2) that allows unauthenticated attackers to perform full Account Takeover (ATO) by exploiting a password reset token leakage flaw. The application incorrectly embeds the password reset token in a hidden HTML input field on the reset page, which is accessible to anyone via a simple GET request using the victim's email address. The vulnerability was disclosed and patched on February 13, 2026. It carries a CVSS v3 base score of 9.8 (Critical) (GitHub Advisory, Known Security Advisory).
The root cause lies in two flawed functions — getContent() and postContent() — within Idno/Pages/Account/Password/Reset.php. Both functions called $user->getPasswordRecoveryCode() and overwrote the user-supplied code with the actual stored token, which was then either rendered in the HTML response or used to skip validation entirely (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor; CWE-640: Weak Password Recovery Mechanism for Forgotten Password). Because the reset page at /account/password/reset/ is accessible via an unauthenticated GET request with only the victim's email as a parameter, an attacker can programmatically extract the secret token from the hidden form field without any privileges. A secondary issue also allowed user enumeration via distinct error messages on the forgot-password handler (GitHub Advisory, Patch Commit).
Successful exploitation enables a fully unauthenticated attacker to take over any user account on the platform — including administrator accounts — without requiring access to the victim's email inbox. This results in a total loss of confidentiality (access to private posts and personal data), integrity (ability to modify or delete content), and availability (ability to lock out legitimate users). The ease of exploitation and lack of any prerequisite make this a high-risk vulnerability for any publicly accessible Known instance (Known Security Advisory).
A proof-of-concept (PoC) exploit is publicly referenced in the GitHub security advisory, demonstrating exploitation via a simple curl command. The EPSS score is approximately 0.098% (0.329% per GitHub Advisory), placing it in the 56th percentile for exploitation likelihood within 30 days. There is no confirmed evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported (GitHub Advisory, Feedly).
/account/password/ endpoint (e.g., using a browser or curl -X POST).curl 'https://target.example.com/account/password/reset/?email=victim@example.com'.<input type="hidden" name="code" value="[TOKEN]">)./account/password/reset/ with the extracted token, the victim's email, and a new attacker-chosen password./account/password/reset/ with an email query parameter from IP addresses that did not initiate the original password reset flow; automated/scripted request patterns (rapid sequential requests for multiple email addresses)./account/password/reset/?email=<victim_email> from unexpected or external IP addresses; POST requests to the same endpoint shortly after, indicating token use.The vulnerability is fixed in Known version 1.6.3, released February 13, 2026. The patch modifies Reset.php to validate the user-supplied code against the stored code using hash_equals() (timing-safe comparison) and ensures the stored token is never passed to the HTML template. The forgot-password handler was also updated to always return the same response regardless of whether the email exists, preventing user enumeration. All users running Known ≤ 1.6.2 should upgrade to 1.6.3 immediately; no configuration-based workaround is available as a substitute (Known Release 1.6.3, Patch Commit).
The vulnerability was reported by security researcher IamLeandrooooo and published by the Known maintainer (benwerd) on February 13, 2026. A technical write-up was published on dev.to describing the flaw as "the over-helpful doorman" and detailing the full account takeover scenario. Coverage also appeared on The Hacker Wire and infinitsec.net shortly after disclosure. No major vendor statements beyond the official advisory have been identified (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."