CVE-2026-81179: SysReptor: Host header injection might allow account takeover

Published Sep 18, 2026
·
Updated

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWEDHOSTS with a wildcard accept an attacker-controlled Host header when generating a password reset link. An unauthenticated attacker can request a reset email whose link points to an attacker-controlled system, and a victim who follows that link can disclose the reset token, allowing the attacker to reset the victim's password and take over the account. Exploitation also requires a configured email gateway and an email address for the victim, while some reverse proxy configurations may reject the hostile Host header. This issue is fixed in version 2026.58.

Affected Software

1 affected component
SysReptor<2026.58

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SysReptor to a version that resolves this vulnerability.

    Fixed in 2026.58
  2. Configuration

    Ensure ALLOWED_HOSTS does not use a wildcard that would allow an attacker-controlled Host header when generating password reset links (issue described for installations prior to 2026.58 that configure ALLOWED_HOSTS with a wildcard).

    SysReptor ALLOWED_HOSTS = (no wildcard for untrusted hosts)

Event History

Sep 18, 2026
CVE Published
via MITRE·05:45 PM
Data Sourced
via MITRE·05:45 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Affected deployments are SysReptor versions before 2026.58 that have password reset by email enabled and configure ALLOWED_HOSTS with a wildcard. Exploitation also depends on a configured email gateway; some reverse proxies may reject the malicious Host header.

2

What does an attacker need to exploit it?

The attacker does not need an account, but needs the target victim's email address and must be able to submit a password-reset request with an attacker-controlled Host header. The victim must then follow the reset link delivered by email and disclose the reset token to the attacker-controlled system.

3

Are default configurations affected?

The provided information identifies the wildcard ALLOWED_HOSTS setting and email-based password resets as required conditions. It does not state whether either setting is enabled by default.

4

What can be done before upgrading?

Disable email password resets or remove the wildcard from ALLOWED_HOSTS. Ensure any reverse proxy rejects untrusted Host headers; this may prevent the hostile header from reaching SysReptor.

5

How can administrators determine whether they are affected?

Check whether the installation is older than 2026.58, has email password resets enabled, uses a wildcard in ALLOWED_HOSTS, and has a configured email gateway. Also review reverse-proxy Host-header validation, since configurations that reject hostile Host headers may block exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203