PatchSiren cyber security CVE debrief
CVE-2026-43935 e107inc CVE debrief
A Host Header Injection vulnerability in e107 CMS prior to version 2.3.4 allows attackers to manipulate password reset links by controlling the Host header, potentially enabling phishing attacks and account takeover. The vulnerability affects the password reset functionality, a critical authentication component. The issue was disclosed on 2026-05-26 and fixed in e107 version 2.3.4. Multiple commits address the vulnerability. The CVSS 3.1 score of 8.1 reflects high impact on confidentiality and integrity with network attack vector, low attack complexity, no privileges required, and user interaction required.
- Vendor
- e107inc
- Product
- e107
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-26
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-05-26
- Advisory updated
- 2026-05-26
Who should care
Organizations running e107 CMS versions prior to 2.3.4; security teams responsible for web application authentication flows; system administrators managing e107 deployments; users with accounts on affected e107 installations
Technical summary
The e107 CMS password reset functionality prior to version 2.3.4 fails to properly validate the Host header when generating password reset emails. An attacker can supply a malicious Host header value that the application incorporates into password reset URLs sent to users. When recipients click these manipulated links, they are directed to attacker-controlled infrastructure while presenting legitimate-appearing reset tokens. This enables credential harvesting and account compromise. The vulnerability stems from reliance on client-supplied Host headers (CWE-807) without adequate input validation (CWE-20). Remediation involves upgrading to e107 2.3.4 and implementing server-level Host header validation.
Defensive priority
high
Recommended defensive actions
- Upgrade e107 CMS to version 2.3.4 or later to remediate this vulnerability
- Configure web server to validate Host headers and reject requests with unexpected or malformed Host values
- Implement additional email verification steps for password reset requests to reduce impact of potential link manipulation
- Review web server and reverse proxy configurations to ensure Host header is properly sanitized before reaching application
- Monitor authentication logs for anomalous password reset request patterns or reset link usage from unexpected referrers
Evidence notes
CVE published 2026-05-26T16:16:25.390Z; modified 2026-05-26T19:26:42.643Z. NVD status: Deferred. Fix version 2.3.4 confirmed in advisory. Three commits referenced for remediation. CWE-20 (Improper Input Validation) and CWE-807 (Reliance on Untrusted Inputs in a Security Decision) identified.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-43935 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-43935
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-43935 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43935
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/e107inc/e107/commit/04511f9f1d6e97c31ba7cc5bf7f1f9a19d221db6
-
Source reference
Unverified legacy reference
URL: https://github.com/e107inc/e107/commit/b0dee8234e273debbf7a8ae054de464f1008f357
-
Source reference
Unverified legacy reference
URL: https://github.com/e107inc/e107/commit/c4f9f71b0fd695545d0f09e2277b6f70ff4660fc
-
Source reference
Unverified legacy reference
URL: https://github.com/e107inc/e107/security/advisories/GHSA-7pmw-jwvr-cq2x
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.