Overview
The target platform's password-change endpoint could be called without authentication, and it did not verify the current password. A unified member number and a new password were enough to change the password of any account immediately. Combined with a separately found object-level authorization flaw, a single member number obtained by sequential enumeration was enough to take over an account.
This is an abridged record. The product name, vendor name, paths, parameter names and reproduction steps are masked.
Disclosure details
- ID: FVE-2026-8617-74507
- Group: Web
- Status: Published
- Severity: Critical (CVSS 9.8,
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) - Submitted: 2026-05-18, issued: 2026-05-29
- Visibility: Redacted
Attack flow
[Step 1] Obtain a member-number-based identifier from the auth token issuance flow
- Requires the object-level authorization flaw as a precondition
[Step 2] Obtain the unified member number
- Completion of authentication is not explicitly verified
[Step 3] Send the password-change request
- No current-password check
- Returns a success response even in an anonymous state
Impact
- Another user's password can be changed immediately
- The victim can no longer log in with their existing password
- Taking over the account can cascade to linked services
- Scales to mass sequential enumeration
Remediation
- Add authentication checks to the password-change endpoint.
- Verify on the server that the requester owns the target account.
- Require the current password or an alternative authentication factor.
- Block the preceding object-level authorization flaw first.
Platform evaluation
- Medium
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L/SH:D/DO:A
CWE
- CWE-620: Unverified Password Change
- CWE-306: Missing Authentication for Critical Function