rootpwn

medium · CVSS v3 5.4 · CVSS v4 5.3 · EPSS 0.00198

CVE-2026-105131

ezBookkeeping 1.2.0 through 2.0.0 has a privilege escalation flaw that lets an attacker with an API token obtain a full session token. The f

Overview

ezBookkeeping 1.2.0 through 2.0.0 has a privilege escalation flaw that lets an attacker with an API token obtain a full session token. The flaw occurs because the token refresh endpoint does not validate the token type. This can allow attackers to bypass token expiry and allowlists, gaining elevated access.

Description

ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to obtain a full session token via /api/v1/tokens/refresh.json. Because TokenRefreshHandler never checks token type, attackers can exchange short-lived or IP-restricted API tokens for 30-day normal session tokens that bypass API token expiry and allowlists.

Impact

Confidentiality: attackers can gain full session tokens, accessing sensitive financial data. Integrity: elevated privileges can modify records. Availability: not directly impacted. Defenders: system administrators and security teams must ensure tokens are properly validated.

Remediation

Apply the official patch to ezBookkeeping 2.0.1 or later. If patch unavailable, restrict API token usage to read-only endpoints and enforce IP restrictions. Disable the /api/v1/tokens/refresh.json endpoint for API tokens or add token type validation. Rotate all API tokens and monitor for abnormal token refresh activity.

Risk context

The vulnerability has a medium severity score (CVSS 5.4) and a very low EPSS of 0.00198, indicating it is unlikely to be widely exploited. Organizations using the affected versions should still apply the fix promptly to prevent potential privilege escalation.

Affected products

  • ezBookkeeping 1.2.0
  • ezBookkeeping 2.0.0

Scores

Severity
medium
CVSS v2
5.5
CVSS v3
5.4
CVSS v4
5.3
EPSS
0.00198

privilege escalation token abuse API session hijacking ezBookkeeping medium severity EPSS low

← All CVEs