ZeroHour

CVE-2026-6285

niche

Weak Password Recovery in Ankaref LIBRID/LIBREF Enables Account Takeover

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-6285 is a weak password recovery mechanism (CWE-640) in the forgotten-password function of Ankaref's LIBRID/LIBREF, allowing an unauthenticated, network-adjacent attacker to exploit the password recovery flow and reset another account's password. The CVSS vector (AV:N/AC:L/PR:N/UI:N, C:H) indicates the flaw is reachable over the network without credentials or user interaction and primarily yields high-impact confidentiality loss through account takeover. It affects LIBRID/LIBREF versions from 2.01.0.2183 through 10092026. Any deployment running the affected version range is exposed wherever its recovery endpoint is reachable by untrusted users. There is currently no known public proof-of-concept, no CISA KEV listing, and no confirmed in-the-wild exploitation; the vendor was contacted early about the disclosure but did not respond, and no patched release is documented in the advisory data.

What to do: No fixed version is documented because the vendor did not respond, so mitigate by restricting network access to the LIBRID/LIBREF management and password-recovery interface to trusted users or networks. Review recent password resets and account changes for signs of tampering, and monitor TR USOM and the vendor for an updated advisory and patch.

Affected
Ankaref Innovation and Technology Inc. LIBRID/LIBREF2.01.0.2183 through 10092026
Estimated exposure
nicheunknown, likely limited to institutional library deployments (no public install counts available) — LIBRID/LIBREF is a niche vertical product from a Turkish RFID/library-automation vendor, primarily deployed in libraries and institutions, and no public installation or internet-exposure counts exist to quantify installations.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Weakness
CWE-640
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.