CVE-2026-105131: mayswind ezBookkeeping 1.2.0 before 2.0.1 Privilege Escalation via Token Refresh Endpoint
ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to obtain a full session token via /api/v1/tokens/refresh.json. Because TokenRefreshHandler never checks token type, attackers can exchange short-lived or IP-restricted API tokens for 30-day normal session tokens that bypass API token expiry and allowlists.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ezBookkeepingto a version that resolves this vulnerability.Fixed in 2.0.1
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must already possess an API token. No user interaction is required, and the attack can be performed remotely.
What security restrictions can be bypassed through exploitation?
An attacker can exchange a short-lived or IP-restricted API token for a normal session token valid for 30 days. The resulting session token bypasses API-token expiry and IP allowlist restrictions.
What is the available remediation?
Upgrade ezBookkeeping to version 2.0.1, which is the release identified as fixing the issue.