Junglewise Threat Intelligence

CVE-2026-12066: PbootCMS weak password recovery in MemberController

CVE-2026-12066 · Severity: high · CVSS 7.3 · Published 2026-06-12

Executive brief

PbootCMS, a popular content management system, contains a security flaw in its password recovery system. This vulnerability allows an unauthorized person to potentially bypass security checks and reset user passwords remotely. If exploited, an attacker could gain full control over user accounts, leading to data theft or unauthorized website modifications.

Technical details

A weak password recovery vulnerability (CWE-640) exists in PbootCMS versions up to 3.2.12. The flaw is located in the 'retrieve' function within 'apps/home/controller/MemberController.php'. By manipulating specific arguments including username, password, email, and checkcode, a remote attacker can bypass intended security logic to reset account passwords. This is a network-based attack that requires no prior authentication or user interaction. Public exploit code has been released, increasing the risk of active exploitation.

Affected products

  • PbootCMS PbootCMS up to 3.2.12

Timeline

  • 2026-05-15: disclosed: Issue reported on GitHub repository
  • 2026-06-12: advisory: CVE-2026-12066 published by NVD/VulDB

References

Related threats