CVE-2026-94105: nivocart Vulnerability (CVSS 5.3) — Fix & Details
CVE-2026-94105 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale . NivoCart through 2.4.0 contains a destructive configuration write vulnerability in the admin password reset controller that allows unauthenticated attackers to disable password recovery by supplying an invalid code parameter. Attackers can send a GET request with a missing or incorrect code to rewrite the config_password setting to 0, disabling self-service password recovery until an administrator manually re-enables it. .
NivoCart through 2.4.0 contains a destructive configuration write vulnerability in the admin password reset controller that allows unauthenticated attackers to disable password recovery by supplying an invalid code parameter. Attackers can send a GET request with a missing or incorrect code to rewrite the config_password setting to 0, disabling self-service password recovery until an administrator manually re-enables it.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Source: CNA advisory (CVE.org). NVD analysis pending.
Frequently Asked Questions
How Strix found a critical auth bypass in etcd Strix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
Autonomous Pentesting AI agents that find and validate exploitable vulnerabilities like this one across your applications.
PR Reviews Pentest every pull request so vulnerable code is caught before it ships to production.
AI Penetration Testing How AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
CVE-2026-9408 A vulnerability was detected in Totolink A8000RU 7.1cu.643_b… 9.8
CVE-2026-94083 Suricata before 8.0.7 has a DoH2 type confusion that can cau… 9.4
CVE-2026-94084 Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-f… 9.4
CVE-2026-9409 A flaw has been found in Sushmi-pal Invoice-System up to a0a… 4.3
CVE-2026-9410 A vulnerability has been found in Sushmi-pal Invoice-System … 4.3
CVE-2026-94104 NivoCart through 2.4.0 contains an arbitrary file upload vul… 8.8
CVE-2026-94106 getID3 before 1.9.26 contains an OS command injection vulner… 8.8
CVE-2026-94107 NivoCart through 2.4.0 contains a predictable password reset… 8.1
CVE-2026-94108 getID3 through 1.9.26 contains an XML external entity inject… 6.5
CVE-2026-94109 openEQUELLA versions before 2026.1.0 contain a remote code e… 8.8
CVE-2026-9411 A vulnerability was found in SourceCodester Indian Invoicing… 6.3
CVE-2026-94111 Tencent BrowserSkill through 0.3.0 contains an authenticatio… 6.6
Are you affected by CVE-2026-94105 ?
Run a free Strix scan to check your systems for this vulnerability.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
