๐Ÿ” CVE Alert

CVE-2026-105131

MEDIUM 5.4

mayswind ezBookkeeping 1.2.0 before 2.0.1 Privilege Escalation via Token Refresh Endpoint

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to obtain a full session token via /api/v1/tokens/refresh.json. Because TokenRefreshHandler never checks token type, attackers can exchange short-lived or IP-restricted API tokens for 30-day normal session tokens that bypass API token expiry and allowlists.

CWE CWE-863
Vendor mayswind
Product ezbookkeeping
Published Oct 4, 2026
Stay Ahead of the Next One

Get instant alerts for mayswind ezbookkeeping

Be the first to know when new medium vulnerabilities affecting mayswind ezbookkeeping are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

mayswind / ezBookkeeping
1.2.0 < 2.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/mayswind/ezbookkeeping/security/advisories/GHSA-wq25-mpcf-2mfc github.com: https://github.com/mayswind/ezbookkeeping/commit/9a92b07be8a7034665abfdb35b036210a1d57bf9 github.com: https://github.com/mayswind/ezbookkeeping/releases/tag/v2.0.1 github.com: https://github.com/mayswind/ezbookkeeping/blob/v2.0.0/pkg/api/tokens.go#L327-L380 github.com: https://github.com/mayswind/ezbookkeeping vulncheck.com: https://www.vulncheck.com/advisories/mayswind-ezbookkeeping-1.2.0-before-2.0.1-privilege-escalation-via-token-refresh-endpoint

Credits

EVIL0RD