Statping-ng Password Reset Vulnerability in Users API Endpoint
Vulnerability
A vulnerability in Statping-ng version 0.91.0 allows remote attackers to perform account takeover by resetting the passwords of administrators. This is achieved by sending a crafted POST request to the '/api/users' endpoint, using a non-privileged API token.
Impact
Exploitation of this vulnerability grants the attacker full administrative control over the Statping-ng application.
Added: Feb 11, 2026, 8:20 PM
Updated: Feb 11, 2026, 8:20 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
5.0exploitability
6.6remediation
0.0relevance
3.0threat
6.4urgency
2.9incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
