Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-24467

35
FAUCET Score

OpenAEV versions 1.0.0 through 2.0.12 contain a critical account takeover vulnerability in the password reset functionality. The flaw stems from non-expiring password reset tokens that are only 8 digits long, allowing attackers to mass-generate and efficiently brute-force valid tokens to reset any user's password without authentication. Because user email addresses are exposed by design within the platform, even administrator accounts can be compromised with minimal reconnaissance. This vulnerability affects all registered user accounts and enables complete platform compromise through unauthorized access to sensitive simulation data and agent payloads. The vulnerability presents a critical attack surface with a CVSS score of 9.8, requiring no authentication, user interaction, or specialized network access. An unauthenticated remote attacker over the network can execute the attack with low complexity, achieving high impact across confidentiality, integrity, and availability. An automated attack generating 2,000 valid tokens requires approximately 500 seconds to brute-force a password reset token at typical request rates, making this a trivially executable attack that scales reliably across multiple accounts. While not currently listed in the Known Exploited Vulnerabilities catalog, this vulnerability is marked as active on threat tracking lists and has elevated attention from the security community given its severity and ease of exploitation. The EPSS score of 0.0018 indicates this represents a high-risk threat. Organizations running OpenAEV should immediately upgrade to version 2.0.13 to remediate this critical vulnerability, as the attack requires no specialized tools or deep technical knowledge to execute at scale.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.0, < 2.0.13CPE matchmatch criteria
cpe:2.3:a:filigran:openaev:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.0CRITICAL

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.90%
Probability of exploitation in next 30 days
EPSS Percentile
56.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0090 is in the 41st percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / OpenAEV-Platform/openaev/blob/82fa7d0009017110c9b509d0dc1b3a78164259dd/openaev-api/src/main/java/io/openaev/rest/user/UserApi.java
Product
github.com / OpenAEV-Platform/openaev/commit/c09a4e71ea76d26fc28c9b51c76bca89a902df4f
Patch
github.com / OpenAEV-Platform/openaev/releases/tag/2.0.13
Product
github.com / OpenAEV-Platform/openaev/security/advisories/GHSA-vcjx-vw28-25p2
ExploitVendor Advisory