CVE-2026-3186 is a vulnerability in feiyuchuixue sz-boot-parent up to version 1.3.2-beta, specifically impacting the password reset functionality within the /api/admin/sys-user/reset/password/ endpoint. Manipulating the userId argument can lead to the use of a default password, affecting szadmin sz_boot_parent. This medium-severity vulnerability (CVSS 6.3) allows for remote attacks with low complexity and requires low privileges, potentially leading to limited impact on confidentiality, integrity, and availability. While a public exploit has been disclosed, there is no evidence of active exploitation, and it lacks Metasploit or ExploitDB modules, as well as significant community discussion or media coverage. Upgrading to version 1.3.3-beta, which includes authorization validation for the password reset interface, remediates this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.9.0CPE matchmatch criteria | cpe:2.3:a:szadmin:sz-boot-parent:*:*:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:szadmin:sz-boot-parent:1.0.0:beta:*:*:*:*:*:* | ||
1.0.1CPE matchmatch criteria | cpe:2.3:a:szadmin:sz-boot-parent:1.0.1:beta:*:*:*:*:*:* | ||
1.0.2CPE matchmatch criteria | cpe:2.3:a:szadmin:sz-boot-parent:1.0.2:beta:*:*:*:*:*:* | ||
1.1.0CPE matchmatch criteria | cpe:2.3:a:szadmin:sz-boot-parent:1.1.0:beta:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.