CVE-2026-90562: Insufficient Entropy in langbot-app LangBot
LangBot versions from 4.0.8.1 up to but not including 4.10.11 have a vulnerability where password recovery keys are generated with only 24 bits of entropy and the reset-password endpoint lacks rate limiting. This allows remote attackers who know the administrator email to exhaust the keyspace via concurrent requests and reset the admin password, potentially gaining account access.
AI Analysis
Technical Summary
CVE-2026-90562 affects LangBot before version 4.10.11. The vulnerability arises because password recovery keys are generated with insufficient entropy (24 bits), making them guessable through brute force. Additionally, the unauthenticated reset-password endpoint does not implement rate limiting, enabling attackers to rapidly attempt many keys. An attacker who knows the administrator's email can exploit this to exhaust the keyspace and reset the administrator password, thereby gaining unauthorized access.
Potential Impact
An attacker can gain unauthorized administrative access by exploiting the weak entropy in password recovery keys combined with the lack of rate limiting on the reset-password endpoint. This compromises account security and potentially the entire system managed by the administrator.
Mitigation Recommendations
A fix is available in LangBot version 4.10.11 and later. Users should upgrade to version 4.10.11 or newer to address this vulnerability. Until then, implementing rate limiting on the reset-password endpoint and increasing entropy for recovery keys can reduce risk.
CVE-2026-90562: Insufficient Entropy in langbot-app LangBot
Description
LangBot versions from 4.0.8.1 up to but not including 4.10.11 have a vulnerability where password recovery keys are generated with only 24 bits of entropy and the reset-password endpoint lacks rate limiting. This allows remote attackers who know the administrator email to exhaust the keyspace via concurrent requests and reset the admin password, potentially gaining account access.
CVSS v4.0
Score 9.2critical
Affected software
langbot-app
LangBot
pkg:github/langbot-app/LangBotRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-90562 affects LangBot before version 4.10.11. The vulnerability arises because password recovery keys are generated with insufficient entropy (24 bits), making them guessable through brute force. Additionally, the unauthenticated reset-password endpoint does not implement rate limiting, enabling attackers to rapidly attempt many keys. An attacker who knows the administrator's email can exploit this to exhaust the keyspace and reset the administrator password, thereby gaining unauthorized access.
Potential Impact
An attacker can gain unauthorized administrative access by exploiting the weak entropy in password recovery keys combined with the lack of rate limiting on the reset-password endpoint. This compromises account security and potentially the entire system managed by the administrator.
Mitigation Recommendations
A fix is available in LangBot version 4.10.11 and later. Users should upgrade to version 4.10.11 or newer to address this vulnerability. Until then, implementing rate limiting on the reset-password endpoint and increasing entropy for recovery keys can reduce risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-12T11:13:43.327Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa682ac55bf5e2cf583e18a
Added to database: 09/13/2026, 11:02:04 UTC
Last enriched: 09/13/2026, 11:17:33 UTC
Last updated: 09/13/2026, 15:28:01 UTC
Views: 29
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.