Executive brief
LIBRID/LIBREF is an identity and access management system used by organizations to manage user authentication and account recovery. A flaw in its password recovery mechanism allows attackers to bypass security controls and reset user passwords without proper authorization, potentially leading to unauthorized account access and data compromise.
Technical details
The vulnerability is a weak password recovery mechanism in the forgotten password functionality of LIBRID/LIBREF. The password reset process lacks adequate security controls or validation checks, allowing attackers to exploit the recovery flow to reset passwords for any user account. This could be achieved through predictable tokens, insufficient verification, or other flaws in the recovery workflow. The issue affects versions 2.01.0.2183 through versions prior to 18.9.26.2319. Organizations using vulnerable versions should update immediately to patch this authentication bypass vector.
Affected products
- Ankaref Innovation and Technology Inc. LIBRID/LIBREF 2.01.0.2183 before 18.9.26.2319
Timeline
- 2026-09-10: disclosed