medium · CVSS v3 5.4 · CVSS v4 5.3 · EPSS 0.00198
CVE-2026-105131
ezBookkeeping 1.2.0 through 2.0.0 has a privilege escalation flaw that lets an attacker with an API token obtain a full session token. The f
Overview
ezBookkeeping 1.2.0 through 2.0.0 has a privilege escalation flaw that lets an attacker with an API token obtain a full session token. The flaw occurs because the token refresh endpoint does not validate the token type. This can allow attackers to bypass token expiry and allowlists, gaining elevated access.
Description
ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to obtain a full session token via /api/v1/tokens/refresh.json. Because TokenRefreshHandler never checks token type, attackers can exchange short-lived or IP-restricted API tokens for 30-day normal session tokens that bypass API token expiry and allowlists.
Impact
Confidentiality: attackers can gain full session tokens, accessing sensitive financial data. Integrity: elevated privileges can modify records. Availability: not directly impacted. Defenders: system administrators and security teams must ensure tokens are properly validated.
Remediation
Apply the official patch to ezBookkeeping 2.0.1 or later. If patch unavailable, restrict API token usage to read-only endpoints and enforce IP restrictions. Disable the /api/v1/tokens/refresh.json endpoint for API tokens or add token type validation. Rotate all API tokens and monitor for abnormal token refresh activity.
Risk context
The vulnerability has a medium severity score (CVSS 5.4) and a very low EPSS of 0.00198, indicating it is unlikely to be widely exploited. Organizations using the affected versions should still apply the fix promptly to prevent potential privilege escalation.
Affected products
- ezBookkeeping 1.2.0
- ezBookkeeping 2.0.0
Scores
- Severity
- medium
- CVSS v2
- 5.5
- CVSS v3
- 5.4
- CVSS v4
- 5.3
- EPSS
- 0.00198