critical · CVSS v3 8.1
CVE-2026-81179
SysReptor, a pentest reporting platform, has a critical flaw that allows an attacker to hijack password reset links via a Host header inject
Overview
SysReptor, a pentest reporting platform, has a critical flaw that allows an attacker to hijack password reset links via a Host header injection when ALLOWED_HOSTS is set to a wildcard. This can lead to account takeover if the victim follows the forged link. The issue is fixed in version 2026.58.
Description
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header when generating a password reset link. An unauthenticated attacker can request a reset email whose link points to an attacker-controlled system, and a victim who follows that link can disclose the reset token, allowing the attacker to reset the victim's password and take over the account. Exploitation also requires a configured email gateway and an email address for the victim, while some reverse proxy configurations may reject the hostile Host header. This issue is fixed in version 2026.58.
Impact
Confidentiality, Integrity, and Availability are at risk: attackers can gain unauthorized access to user accounts, compromising sensitive data and potentially disrupting reporting services. Defenders should treat this as a high-impact vulnerability affecting all installations with email-based password reset enabled.
Remediation
Upgrade to SysReptor 2026.58 or later. If upgrade is not possible, disable password reset by email or set ALLOWED_HOSTS to a strict list of trusted domains. Ensure the email gateway is properly configured and monitor for suspicious reset emails.
Risk context
Severity is critical with CVSS 8.1. No EPSS data available. Immediate action is recommended due to potential account takeover.
Affected products
- SysReptor
Scores
- Severity
- critical
- CVSS v2
- 9.4
- CVSS v3
- 8.1
- CVSS v4
- —
- EPSS
- —