Junglewise Threat Intelligence

CVE-2026-6285: Ankaref LIBRID/LIBREF weak password recovery mechanism

CVE-2026-6285 · Severity: high · CVSS 7.5 · Published 2026-09-10

Technologies: Ankaref Innovation and Technology Inc. LIBRID/LIBREF. Vendors: Ankaref Innovation and Technology Inc..

Executive brief

LIBRID/LIBREF is an identity and access management system used by organizations to manage user authentication and account recovery. A flaw in its password recovery mechanism allows attackers to bypass security controls and reset user passwords without proper authorization, potentially leading to unauthorized account access and data compromise.

Technical details

The vulnerability is a weak password recovery mechanism in the forgotten password functionality of LIBRID/LIBREF. The password reset process lacks adequate security controls or validation checks, allowing attackers to exploit the recovery flow to reset passwords for any user account. This could be achieved through predictable tokens, insufficient verification, or other flaws in the recovery workflow. The issue affects versions 2.01.0.2183 through versions prior to 18.9.26.2319. Organizations using vulnerable versions should update immediately to patch this authentication bypass vector.

Affected products

  • Ankaref Innovation and Technology Inc. LIBRID/LIBREF 2.01.0.2183 before 18.9.26.2319

Timeline

  • 2026-09-10: disclosed

References

Related threats