CVE-2026-6285 PUBLISHED

Improper Authentication in Ankaref's LIBRID/LIBREF

Assigner: TR-CERT
Reserved: 14.04.2026 Published: 10.09.2026 Updated: 10.09.2026

Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation.

This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 7.5

Product Status

Vendor Ankaref Innovation and Technology Inc.
Product LIBRID/LIBREF
Versions Default: unknown
  • affected from 2.01.0.2183 to 10092026 (incl.)

Credits

  • Ahmet DURMUŞ finder

References

Problem Types

  • CWE-640 Weak Password Recovery Mechanism for Forgotten Password CWE

Impacts

  • CAPEC-50 Password Recovery Exploitation