CVE-2026-12066: PbootCMS Weak Password Recovery RCE – CVSS 7.3 HIGH
PbootCMS versions up to 3.2.12 contain a flaw in the password recovery mechanism that allows attackers to bypass intended security controls. The vulnerability exists in the component that handles password resets and account recovery, specifically in how it validates and processes recovery-related parameters. An attacker can exploit this remotely without authentication to recover user accounts or reset passwords that should be protected, potentially gaining unauthorized access to user accounts.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.3 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Weaknesses (CWE)
- CWE-640
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-12 / 2026-06-17
NVD description (verbatim)
A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler. The manipulation of the argument username/password/email/checkcode results in weak password recovery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
6 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-12066 is a weak password recovery vulnerability in PbootCMS affecting versions through 3.2.12. The flaw resides in the retrieve() function within apps/home/controller/MemberController.php. The password handler component fails to properly validate and sanitize the username, password, email, and checkcode parameters during the recovery process. This CWE-640 (Weak Password Recovery Mechanism) issue allows remote, unauthenticated attackers to manipulate recovery flows to compromise account security. The CVSS 3.1 score of 7.3 (HIGH) reflects the network-accessible nature, low complexity of exploitation, and impact across confidentiality, integrity, and availability.
Business impact
Compromised user accounts represent significant operational and reputational risk. If PbootCMS is deployed for customer-facing applications, content management, or e-commerce, successful exploitation could expose sensitive user data, enable unauthorized modifications to site content, and erode customer trust. Attackers can systematically recover or reset accounts belonging to high-value users, administrators, or employees. Organizations should assess whether user data subject to regulatory frameworks (GDPR, HIPAA, PCI-DSS) is managed through affected instances.
Affected systems
PbootCMS versions up to and including 3.2.12 are confirmed vulnerable. Organizations running PbootCMS in production should verify their installed version immediately. Web-accessible PbootCMS installations used for content management, community platforms, or any application handling user authentication are directly at risk.
Exploitability
This vulnerability is exploitable remotely without authentication, credentials, or user interaction. Public exploit code has been released, meaning threat actors have functional proof-of-concept tooling available. The attack vector is network-based with low complexity, making it likely to be rapidly weaponized by opportunistic threat actors scanning for vulnerable instances. Organizations should treat this as high-priority from an exploitability perspective.
Remediation
Upgrade PbootCMS to a patched version released after the 3.2.12 branch. Verify the specific version number against the official PbootCMS vendor advisory to ensure the patch addresses CVE-2026-12066. As an interim measure, implement authentication-layer controls: restrict access to password recovery endpoints by IP allowlist if feasible, monitor recovery request logs for anomalies, and enforce rate limiting on recovery submissions. Consider temporarily disabling self-service password recovery if operationally acceptable while patches are tested and deployed.
Patch guidance
Consult the official PbootCMS project repository or vendor security advisories to identify the first patched version that remedies CVE-2026-12066. Patch releases typically address the weak validation logic in the retrieve() function. Organizations should test patches in a non-production environment before rollout to confirm functionality and rule out conflicts with custom extensions. Establish a change window aligned with your business cycle for deployment.
Detection guidance
Monitor authentication and password recovery logs for suspicious patterns: multiple failed recovery attempts targeting the same or different accounts from the same IP, recovery requests with unusual parameter values, successful recovery of high-privilege accounts outside normal business hours, and anomalous resets of recently-accessed accounts. Implement Web Application Firewall (WAF) rules to inspect password recovery endpoint traffic for parameter tampering or encoding bypass attempts. Network-level detection can flag POST requests to the MemberController.php retrieve function with suspicious payloads or rapid-fire submissions.
Why prioritize this
This vulnerability warrants immediate attention. The combination of remote exploitability without authentication, publicly available exploit code, HIGH CVSS score, and direct impact on user account security creates urgent business risk. Unlike vulnerabilities requiring user interaction or specialized knowledge, this flaw can be exploited at scale by automated scanning and weaponized code. Organizations should prioritize patching or mitigation within their critical remediation window.
Risk score, explained
The CVSS 3.1 score of 7.3 reflects a HIGH-severity issue with significant real-world impact. The Attack Vector (Network) and Attack Complexity (Low) indicate broad, easy exploitability. Privileges Required (None) and User Interaction (None) eliminate typical friction that might delay attacks. The Confidentiality, Integrity, and Availability impacts are rated Low individually but collectively result in meaningful compromise of user account security. The score does not account for public exploit availability, which amplifies practical risk.
Frequently asked questions
What versions of PbootCMS are affected?
All versions up to and including 3.2.12 are confirmed vulnerable. If you are running PbootCMS, verify your installed version against your admin panel or configuration files. Versions released after 3.2.12 may contain a patch; consult official release notes or security bulletins from the PbootCMS project.
Can this vulnerability be exploited remotely without credentials?
Yes. The vulnerability requires no authentication, valid user credentials, or social engineering. An attacker can access the vulnerable password recovery endpoint directly over the network and manipulate parameters to bypass security controls. The public release of exploit code significantly lowers the barrier to attack.
What should we do if we cannot patch immediately?
Implement compensating controls: restrict password recovery endpoint access via firewall rules or IP allowlists, enable rate limiting on recovery requests, monitor recovery logs for anomalies, and consider disabling self-service recovery temporarily if operationally feasible. These do not fix the vulnerability but reduce exposure window while patches are tested and deployed.
Does this affect all PbootCMS deployments?
Any PbootCMS instance up to version 3.2.12 that is network-accessible and uses the standard password recovery mechanism is at risk. Organizations running custom forks or modified versions should review their code against the affected MemberController.php retrieve() function to determine exposure.
This analysis is provided for informational purposes and should not be considered a substitute for vendor advisories or internal security assessments. Organizations should verify patch availability, version compatibility, and functional impact before implementing remediation. The presence of public exploits does not guarantee that exploitation is occurring in your environment; implement monitoring and detection practices tailored to your infrastructure. Always test patches in non-production environments first. SEC.co makes no warranty regarding the accuracy, completeness, or timeliness of this information relative to emerging threat activity or vendor responses. Source: NVD (public-domain), retrieved 2026-07-20. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2026-35676HIGHphpMyFAQ Unauthenticated Password Reset Vulnerability
- CVE-2026-50635HIGHLimeSurvey Account Takeover via Host Header Injection in Password Reset
- CVE-2026-7459HIGHSimple History WordPress Plugin Account Takeover Vulnerability
- CVE-2026-10169LOWWeak Password Recovery in OUSL-GROUP-BrinaryBrains School Management System
- CVE-2016-20062HIGHSQL Injection in Simply Poll 1.4.1 WordPress Plugin - Unauthenticated Data Theft
- CVE-2016-20063HIGHSQL Injection in Single Personal Message 1.0.3 – Credential & Data Theft Risk
- CVE-2016-20065HIGHUnauthenticated SQL Injection in Product Catalog 8 WordPress Plugin
- CVE-2016-20066HIGHWordPress CP Polls 1.0.8 Persistent XSS Vulnerability