Weak Password Recovery Mechanism for Forgotten Password in AzuraCast - #VU127153
Published: April 23, 2026
AzuraCast
Detailed vulnerability description
The vulnerability allows a remote attacker to take over user accounts and bypass two-factor authentication.
The vulnerability exists due to a weak password recovery mechanism in the ApplyXForwarded middleware and password reset flow when handling a forgot-password request with a client-supplied X-Forwarded-Host header. A remote attacker can send a specially crafted password reset request to take over user accounts and bypass two-factor authentication.
User interaction is required because the victim must click the poisoned password reset link.