CVE-2026-3186 Details
Description
A vulnerability was determined in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this vulnerability is an unknown functionality of the file /api/admin/sys-user/reset/password/ of the component Password Reset Handler. This manipulation of the argument userId causes use of default password. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.3.3-beta addresses this issue. Patch name: aefaabfd7527188bfba3c8c9eee17c316d094802. It is suggested to upgrade the affected component. The project was informed beforehand and acted very professional: "We have added authorization validation to the password reset interface; now only users with the corresponding permissions are allowed to perform password resets."
A vulnerability exists in Feiyuchuixue Sz-Boot-Parent versions through 1.3.2-Beta, allowing users with ordinary permissions to reset the passwords of other users via the API '/api/admin/sys-user/reset/password/{userId}'. This functionality should be restricted to administrators. The passwords are reset to a default value, 'sz123456'. The vulnerability arises from a lack of proper authorization validation on the password reset interface, which has been addressed in version 1.3.3-Beta. The vulnerability can be exploited remotely, and the exploit has been publicly disclosed.
Upgrading to Feiyuchuixue Sz-Boot-Parent version 1.3.3-Beta addresses this vulnerability. The updated version is available on the project's GitHub releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/feiyuchuixue/sz-boot-parent/ | [email protected] | Product |
| https://github.com/feiyuchuixue/sz-boot-parent/commit/aefaabfd7527188bfba3c8c9eee17c316d094802 | [email protected] | Patch |
| https://github.com/feiyuchuixue/sz-boot-parent/releases/tag/v1.3.3-beta | [email protected] | Release Notes |
| https://github.com/yuccun/CVE/blob/main/sz-boot-parent-VPE_Unauthorized_Password_Reset.md | [email protected] | ExploitThird Party Advisory |
| https://vuldb.com/?ctiid.347744 | [email protected] | Permissions RequiredThird Party AdvisoryVDB Entry |
| https://vuldb.com/?id.347744 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.754037 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1393 | Use of Default Password | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| szadmin sz-boot-parent | <= 0.9.0 1.0.0 beta 1.0.1 beta 1.0.2 beta 1.1.0 beta 1.2.0 beta 1.2.1 beta 1.2.2 beta 1.2.3 beta 1.2.4 beta 1.2.5 beta 1.2.6 beta 1.3.0 beta 1.3.1 beta 1.3.2 beta |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Feb 26, 2026 | Initial Analysis | [email protected] |
| Feb 25, 2026 | New CVE Received | [email protected] |