rootpwn

critical · CVSS v3 8.1

CVE-2026-81179

SysReptor, a pentest reporting platform, has a critical flaw that allows an attacker to hijack password reset links via a Host header inject

Overview

SysReptor, a pentest reporting platform, has a critical flaw that allows an attacker to hijack password reset links via a Host header injection when ALLOWED_HOSTS is set to a wildcard. This can lead to account takeover if the victim follows the forged link. The issue is fixed in version 2026.58.

Description

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header when generating a password reset link. An unauthenticated attacker can request a reset email whose link points to an attacker-controlled system, and a victim who follows that link can disclose the reset token, allowing the attacker to reset the victim's password and take over the account. Exploitation also requires a configured email gateway and an email address for the victim, while some reverse proxy configurations may reject the hostile Host header. This issue is fixed in version 2026.58.

Impact

Confidentiality, Integrity, and Availability are at risk: attackers can gain unauthorized access to user accounts, compromising sensitive data and potentially disrupting reporting services. Defenders should treat this as a high-impact vulnerability affecting all installations with email-based password reset enabled.

Remediation

Upgrade to SysReptor 2026.58 or later. If upgrade is not possible, disable password reset by email or set ALLOWED_HOSTS to a strict list of trusted domains. Ensure the email gateway is properly configured and monitor for suspicious reset emails.

Risk context

Severity is critical with CVSS 8.1. No EPSS data available. Immediate action is recommended due to potential account takeover.

Affected products

  • SysReptor

Scores

Severity
critical
CVSS v2
9.4
CVSS v3
8.1
CVSS v4
EPSS

password-reset host-header account-takeover critical email misconfiguration

← All CVEs