top of page
perceptive_background_267k.jpg

OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campaign and tests. Starting in version 1.0.0…

Published:

19 april 2026 om 22:00:00

Alert date:

20 april 2026 om 17:02:28

Source:

nvd.nist.gov

Click to open the original link from this advisory

Identity & Access, Security Tools

OpenAEV versions 1.0.0 to 2.0.12 contain critical password reset vulnerabilities that enable account takeover. Password reset tokens never expire and are only 8 digits long, allowing attackers to accumulate valid tokens over time and brute-force them efficiently. Attackers can generate thousands of valid tokens and brute-force them in approximately 500 seconds at 100 requests per second. The vulnerability affects all registered user accounts including administrators and can lead to full platform compromise. Email addresses are exposed by design, making any registered account vulnerable. Successful exploitation allows access to sensitive simulation data and modification of payloads on deployed agents.

Technical details

Mitigation steps:

Affected products:

OpenAEV

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page