Critical severity9.1NVD Advisory· Published Oct 9, 2026· Updated Oct 9, 2026
CVE-2026-108109
CVE-2026-108109
Description
PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer username can guess the code without attempt limits or lockout, then read the newly set password from the HTTP response to hijack the account.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=2025.3.20
Patches
Vulnerability mechanics
References
4- github.com/hotspotbilling/phpnuxbill/blob/2025.3.13/system/controllers/forgot.phpnvd
- github.com/hotspotbilling/phpnuxbill/commit/c3c2a92d468af91136d747b75142ed72f10320ccnvd
- github.com/hotspotbilling/phpnuxbill/security/advisories/GHSA-337r-rrrc-r559nvd
- www.vulncheck.com/advisories/phpnuxbill-through-2025.3.20-account-takeover-via-brute-forceable-password-reset-codenvd
News mentions
0No linked articles in our index yet.