Weak Password Recovery Mechanism for Forgotten Password in JumpServer - CVE-2023-46138
Published: October 26, 2023 / Updated: April 27, 2026
JumpServer
JumpServer
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use of an unregistered default email address in password reset functionality when processing password reset operations for the default admin account. A remote attacker can register the referenced domain to disrupt password reset functionality and cause a denial of service.
The issue affects the initial admin account that uses the default email address admin@mycompany.com.