CVE-2026-108109
CRITICAL
NVD
CVSS Score
9.1
Severity
CRITICAL
Published
Oct 09, 2026
Vendor
unknown
Description
PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer username can guess the code without attempt limits or lockout, then read the newly set password from the HTTP response to hijack the account.
References
- https://github.com/hotspotbilling/phpnuxbill
- https://github.com/hotspotbilling/phpnuxbill/blob/2025.3.13/system/controllers/forgot.php#L41
- https://github.com/hotspotbilling/phpnuxbill/commit/c3c2a92d468af91136d747b75142ed72f10320cc
- https://github.com/hotspotbilling/phpnuxbill/security/advisories/GHSA-337r-rrrc-r559
- https://www.vulncheck.com/advisories/phpnuxbill-through-2025.3.20-account-takeover-via-brute-forceable-password-reset-code