CVE-2025-6216
nichePredictable Reset Token Enables Authentication Bypass in Allegra Password Recovery
CVE-2025-6216 is a critical, unauthenticated authentication bypass (CVSS 9.8, CWE-640) in the password recovery mechanism of Allegra, Alltena's issue-tracking and workflow management suite. The flaw, tracked by ZDI as ZDI-CAN-27104, arises because the password reset token (calculated alongside its expiry date) is derived from a predictable value, allowing a remote attacker to guess or compute a valid reset token without any credentials or user interaction. By submitting a forged or guessed reset token, the attacker can reset an account password and gain authenticated access to the application with that account's privileges, including potentially administrative access. Any organization running a self-hosted Allegra instance, especially one whose login/password-recovery page is reachable from the internet, is affected. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but EPSS assigns a 34.9% probability of exploitation within 30 days (98th percentile), so defenders should treat this as high risk.
What to do: Upgrade Allegra to the patched release identified in the Alltena/ZDI advisory (specific fixed version not listed in this data). In the meantime, restrict internet exposure of the login and password-recovery endpoints and review account activity for unexpected password resets or unexplained logins, particularly on administrative accounts. Because exploitation requires no credentials, prioritize patching any internet-facing instance.
| Alltena Allegra | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Allegra. Authentication is not required to exploit this vulnerability. The specific flaw exists within the password recovery mechanism. The issue results from reliance upon a predictable value when generating a password reset token. An attacker can leverage this vulnerability to bypass authentication on the application. Was ZDI-CAN-27104.
- Vendors
- alltena
- Products
- allegra
- Weakness
- CWE-640
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.