CRITICAL
9.1 CVE-2026-108109 Published 9 Oct 2026
PHPNuxBill Account Takeover via Password Reset OTP Brute-Force
Worried this affects your website?
PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php.
Unauthenticated attackers who know a customer username can brute-force the 6-digit otp_code because there are no attempt limits or lockout.
- Affected versions: through 2025.3.20
- Precondition: attacker knows a customer username
- Impact: attacker can read the newly set password from the HTTP response and hijack the account
Reference: CVE-2026-108109 on NVD
← Back to Security News