CRITICAL 9.1 CVE-2026-108109 Published 9 Oct 2026

PHPNuxBill Account Takeover via Password Reset OTP Brute-Force

Worried this affects your website?

PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php.

Unauthenticated attackers who know a customer username can brute-force the 6-digit otp_code because there are no attempt limits or lockout.

  • Affected versions: through 2025.3.20
  • Precondition: attacker knows a customer username
  • Impact: attacker can read the newly set password from the HTTP response and hijack the account

Reference: CVE-2026-108109 on NVD

← Back to Security News