SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-16751

MEDIUM · CVSS 6.5 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The emergency recovery approval component in Ente Technologies Ente Museum Server is vulnerable to an authorization bypass, allowing authenticated attackers designated as a victim's emergency contact to circumvent the recovery waiting period. This flaw enables them to execute a crafted `approve-recovery` API request, potentially leading to account takeover. Organizations using this server should prioritize patching this vulnerability to protect user accounts from unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-16751
Severity
MEDIUM
CVSS
6.5
EPSS
0.29%

Original NVD Description

Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum Server allows an authenticated attacker configured as a victim's emergency contact to bypass the configured recovery waiting period and take over the victim's account via a crafted `approve-recovery` API request.