CVE-2026-6285: Improper Authentication in Ankaref's LIBRID/LIBREF
Published Sep 10, 2026
·Updated
Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation.
This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
1 affected component
Ankaref Innovation and Technology Inc. LIBRID/LIBREF>=2.01.0.2183<=10092026
Event History
Sep 10, 2026
CVE Published
via MITRE·01:32 PM
Data Sourced
via MITRE·01:32 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments should be considered affected?
LIBRID/LIBREF versions from 2.01.0.2183 through 10092026 are listed as affected.
2
What access does an attacker need to exploit this issue?
The CVSS vector indicates network-reachable exploitation with low attack complexity. It does not require privileges or user interaction.
3
What is the expected security impact?
The CVSS vector rates confidentiality impact as high. It indicates no integrity or availability impact.