ZeroHour

CVE-2025-6216

niche

Predictable Reset Token Enables Authentication Bypass in Allegra Password Recovery

CVSS 3.0
9.8 critical
EPSS
35%p98
Published
()
Modified
AI analysis

CVE-2025-6216 is a critical, unauthenticated authentication bypass (CVSS 9.8, CWE-640) in the password recovery mechanism of Allegra, Alltena's issue-tracking and workflow management suite. The flaw, tracked by ZDI as ZDI-CAN-27104, arises because the password reset token (calculated alongside its expiry date) is derived from a predictable value, allowing a remote attacker to guess or compute a valid reset token without any credentials or user interaction. By submitting a forged or guessed reset token, the attacker can reset an account password and gain authenticated access to the application with that account's privileges, including potentially administrative access. Any organization running a self-hosted Allegra instance, especially one whose login/password-recovery page is reachable from the internet, is affected. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but EPSS assigns a 34.9% probability of exploitation within 30 days (98th percentile), so defenders should treat this as high risk.

What to do: Upgrade Allegra to the patched release identified in the Alltena/ZDI advisory (specific fixed version not listed in this data). In the meantime, restrict internet exposure of the login and password-recovery endpoints and review account activity for unexpected password resets or unexplained logins, particularly on administrative accounts. Because exploitation requires no credentials, prioritize patching any internet-facing instance.

Affected
Alltena Allegra
Estimated exposure
nichelikely low hundreds to low thousands of self-hosted instances (exact install base unknown) — Allegra is a niche, self-hosted issue-tracking/workflow product with a small enterprise customer base and no public install-count data, so the estimate reflects typical deployment scale for this software class rather than a measured count.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Allegra. Authentication is not required to exploit this vulnerability. The specific flaw exists within the password recovery mechanism. The issue results from reliance upon a predictable value when generating a password reset token. An attacker can leverage this vulnerability to bypass authentication on the application. Was ZDI-CAN-27104.

Vendors
alltena
Products
allegra
Weakness
CWE-640
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.