CVE-2026-6285
nicheWeak Password Recovery in Ankaref LIBRID/LIBREF Enables Account Takeover
CVE-2026-6285 is a weak password recovery mechanism (CWE-640) in the forgotten-password function of Ankaref's LIBRID/LIBREF, allowing an unauthenticated, network-adjacent attacker to exploit the password recovery flow and reset another account's password. The CVSS vector (AV:N/AC:L/PR:N/UI:N, C:H) indicates the flaw is reachable over the network without credentials or user interaction and primarily yields high-impact confidentiality loss through account takeover. It affects LIBRID/LIBREF versions from 2.01.0.2183 through 10092026. Any deployment running the affected version range is exposed wherever its recovery endpoint is reachable by untrusted users. There is currently no known public proof-of-concept, no CISA KEV listing, and no confirmed in-the-wild exploitation; the vendor was contacted early about the disclosure but did not respond, and no patched release is documented in the advisory data.
What to do: No fixed version is documented because the vendor did not respond, so mitigate by restricting network access to the LIBRID/LIBREF management and password-recovery interface to trusted users or networks. Review recent password resets and account changes for signs of tampering, and monitor TR USOM and the vendor for an updated advisory and patch.
| Ankaref Innovation and Technology Inc. LIBRID/LIBREF | 2.01.0.2183 through 10092026 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
- Weakness
- CWE-640
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.