haitam lazaar / lazaarsec
← Back to CVE Registry
CVE-2026-105305.3medium[patched]

Email Verification Bypass via Predictable Token

TARGET ECOSYSTEM / VENDORPie Register
AFFECTED PRODUCTPie Register (<= 3.8.4.9)
CWE CLASSIFICATIONCWE-340: Generation of Predictable Numbers or Identifiers
PUBLISHED DATE2026-06-01

Summary

Pie Register (<= 3.8.4.9) generates account verification tokens using predictable values, allowing unauthenticated attackers to activate newly registered accounts without access to the associated email inbox.