CVE-2026-26273: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-26273 is a Critical Broken Authentication vulnerability in the Known social publishing platform (versions ≤ 1.6.2) that allows unauthenticated attackers to perform full Account Takeover (ATO) by exploiting a password reset token leakage flaw. The application incorrectly embeds the password reset token in a hidden HTML input field on the reset page, which is accessible to anyone via a simple GET request using the victim's email address. The vulnerability was disclosed and patched on February 13, 2026. It carries a CVSS v3 base score of 9.8 (Critical) (GitHub Advisory, Known Security Advisory).

Technical details

The root cause lies in two flawed functions — getContent() and postContent() — within Idno/Pages/Account/Password/Reset.php. Both functions called $user->getPasswordRecoveryCode() and overwrote the user-supplied code with the actual stored token, which was then either rendered in the HTML response or used to skip validation entirely (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor; CWE-640: Weak Password Recovery Mechanism for Forgotten Password). Because the reset page at /account/password/reset/ is accessible via an unauthenticated GET request with only the victim's email as a parameter, an attacker can programmatically extract the secret token from the hidden form field without any privileges. A secondary issue also allowed user enumeration via distinct error messages on the forgot-password handler (GitHub Advisory, Patch Commit).

Impact

Successful exploitation enables a fully unauthenticated attacker to take over any user account on the platform — including administrator accounts — without requiring access to the victim's email inbox. This results in a total loss of confidentiality (access to private posts and personal data), integrity (ability to modify or delete content), and availability (ability to lock out legitimate users). The ease of exploitation and lack of any prerequisite make this a high-risk vulnerability for any publicly accessible Known instance (Known Security Advisory).

Exploitability

A proof-of-concept (PoC) exploit is publicly referenced in the GitHub security advisory, demonstrating exploitation via a simple curl command. The EPSS score is approximately 0.098% (0.329% per GitHub Advisory), placing it in the 56th percentile for exploitation likelihood within 30 days. There is no confirmed evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported (GitHub Advisory, Feedly).

Exploitation steps

  1. Identify target: Locate a publicly accessible Known platform instance running version 1.6.2 or earlier.
  2. Trigger password reset: Submit a password reset request for the victim's email address via the /account/password/ endpoint (e.g., using a browser or curl -X POST).
  3. Retrieve the token: Issue a GET request to the reset page with the victim's email as a parameter: curl 'https://target.example.com/account/password/reset/?email=victim@example.com'.
  4. Extract the token: Parse the HTML response to locate the hidden input field containing the password reset token (e.g., <input type="hidden" name="code" value="[TOKEN]">).
  5. Reset the password: Submit a POST request to /account/password/reset/ with the extracted token, the victim's email, and a new attacker-chosen password.
  6. Log in: Authenticate to the Known platform using the victim's email and the newly set password, achieving full account takeover (Known Security Advisory, Patch Commit).

Indicators of compromise

  • Network: Unusual or repeated GET requests to /account/password/reset/ with an email query parameter from IP addresses that did not initiate the original password reset flow; automated/scripted request patterns (rapid sequential requests for multiple email addresses).
  • Logs: Web server access logs showing GET requests to /account/password/reset/?email=<victim_email> from unexpected or external IP addresses; POST requests to the same endpoint shortly after, indicating token use.
  • Application Behavior: Multiple password reset requests for the same or different accounts in a short time window; accounts reporting unexpected password changes or lockouts without initiating a reset themselves.
  • Authentication Logs: Successful logins from unfamiliar IP addresses or geolocations following a password reset event (Known Security Advisory).

Mitigation and workarounds

The vulnerability is fixed in Known version 1.6.3, released February 13, 2026. The patch modifies Reset.php to validate the user-supplied code against the stored code using hash_equals() (timing-safe comparison) and ensures the stored token is never passed to the HTML template. The forgot-password handler was also updated to always return the same response regardless of whether the email exists, preventing user enumeration. All users running Known ≤ 1.6.2 should upgrade to 1.6.3 immediately; no configuration-based workaround is available as a substitute (Known Release 1.6.3, Patch Commit).

Community reactions

The vulnerability was reported by security researcher IamLeandrooooo and published by the Known maintainer (benwerd) on February 13, 2026. A technical write-up was published on dev.to describing the flaw as "the over-helpful doorman" and detailing the full account takeover scenario. Coverage also appeared on The Hacker Wire and infinitsec.net shortly after disclosure. No major vendor statements beyond the official advisory have been identified (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management