External risk intelligence

Cotonti Predictable Password Recovery Token Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-93868

The vulnerability resides in a password recovery mechanism, which is a standard web application feature designed to be accessible to users over the public internet. Because these authentication-related endpoints are necessary for typical web application operation and must be reachable by external users to function, they are commonly exposed on internet-facing web services.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory describes a critical vulnerability in Cotonti, a web content management system. The system generates password recovery tokens using a predictable method, allowing unauthenticated attackers to potentially reset any user's password, including administrators, by calculating and guessing tokens within a short timeframe. The main concern is confirming relevance and exposure.

  • Predictable tokens allow unauthorized password resets.
  • This impacts core account security and administrator access.
  • Confirm if this system is in use and assess exposure.

Attack Path

How an attacker could exploit the issue

Attackers can exploit this vulnerability by targeting the password recovery feature, which is accessible over the network. By observing the server's date, an attacker can calculate a predictable token and use it to reset any user's password, including administrator accounts. This bypasses standard authentication measures and grants unauthorized access to sensitive information and system control.

  • Entry condition: Network access required.
  • Trigger point: Predictable token in password recovery.
  • Resulting risk: Unauthorized account takeover.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to reset any account's password, including administrator accounts, on affected systems. This is possible because the system generates predictable password recovery tokens, allowing an attacker to precompute and guess the correct token within a short timeframe.

  • Any user account password.
  • Predictable tokens allow guessing.
  • Unauthorized account access.

Operational Fix

Recommended remediation, mitigation, and detection steps

Cotonti, a web content management system, contains a critical vulnerability in its password recovery function that allows unauthenticated attackers to reset any account's password. This issue likely impacts application owners and infrastructure teams responsible for maintaining the web application and its underlying servers. The first practical step is to identify all instances of Cotonti, determine their exposure and business criticality, and then prioritize remediation efforts.

  • Application owners must prioritize this issue.
  • Verify Cotonti instances and their exposure.
  • Plan coordinated remediation and vendor engagement.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Cotonti?

Cotonti is a web content management system (CMS) built with PHP. It provides frameworks for developers to create websites and applications. Because it handles user authentication and account management natively, it is often used for community sites or information portals that require robust user access controls.

What does CVE-2026-93868 mean for password recovery?

This vulnerability relates to CWE-338, which involves the use of a cryptographically weak pseudo-random number generator. In this specific case, Cotonti generates password recovery tokens using the system time. Because this method is predictable, an attacker can mathematically determine valid tokens and gain unauthorized access to any account, including administrative ones.

How do attackers trigger this vulnerability?

An attacker triggers this by initiating a password recovery request and leveraging the server's Date header to narrow down the time-based token generation window. This attack does not require a user to interact with the malicious request; it only requires the attacker to have network access to the password recovery endpoint. Simply disabling the recovery feature or restricting network access prevents the exploitation.

Is my Cotonti instance at risk?

According to Halo Surface Signal, this vulnerability impacts password recovery features, which are typically designed to be accessible to users over the public internet. If your Cotonti deployment is internet-facing, it is likely reachable by attackers who can probe these authentication-related endpoints. Internal-only instances may face a lower immediate risk.

How should I respond to this vulnerability?

Begin by auditing your environment to locate all active Cotonti installations. Once identified, evaluate the necessity of the password recovery function and confirm if it is exposed to external networks. Prioritize securing these instances by following standard development practices, such as applying official patches or coordinating with the vendor for updates.

References