LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
LangBot versions before 4.10.11 suffer from a critical authentication bypass vulnerability rooted in cryptographically weak password recovery mechanisms. The vulnerability stems from generating password reset tokens with only 24 bits of entropy—a keyspace of just 16.7 million possible values—combined with an unauthenticated, rate-unlimited reset endpoint. An attacker who knows the administrator's email address can programmatically exhaust this tiny keyspace through concurrent requests, statistically gaining valid reset tokens and complete account takeover within minutes. This affects any organization deploying LangBot for conversational AI applications, particularly those using it for sensitive operations where administrative access provides lateral movement opportunities or data exfiltration paths.
While this CVE maps to CWE-331 (Insufficient Entropy) rather than specific MITRE ATT&CK techniques, Casky practitioners would detect the attack patterns through skills aligned with credential access and initial access kill chains. A security team using Casky's Claude-powered analysis would observe reconnaissance activity (email validation attempts), followed by rapid, concurrent authentication requests to the unauthenticated endpoint—a pattern inconsistent with legitimate password recovery workflows. The platform's extended reasoning would correlate volumetric reset requests, successful token redemptions, and subsequent privileged actions (admin panel access, configuration changes) into a coherent attack narrative. Practitioners should prioritize immediate patching to 4.10.11+, implement rate limiting on all unauthenticated endpoints, and review access logs for evidence of token enumeration or successful unauthorized admin sessions.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-90562. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation