CVE-2026-40352
Last modified
CVE-2026-40352 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. An authenticated attacker can bypass the "old password" verification by injecting MongoDB query operators. This allows an attacker who has gained a low-privileged session to change the password of their account (or others if combined with ID manipulation) without knowing the current one, leading to full account takeover and persistence. This issue has been fixed in version 4.14.9.5.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fastgpt | Fastgpt | < 4.14.9.5 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-40352?
How severe is CVE-2026-40352?
How do I fix CVE-2026-40352?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-40347Python-Multipart is a streaming multipart parser for Python.…5.3
- CVE-2026-40348Movary is a self hosted web app to track and rate a user's w…7.7
- CVE-2026-40349Movary is a self hosted web app to track and rate a user's w…8.8
- CVE-2026-4035A vulnerability in mlflow/mlflow versions prior to 3.11.0 al…7.7
- CVE-2026-40350Movary is a self hosted web app to track and rate a user's w…8.8
- CVE-2026-40351FastGPT is an AI Agent building platform. In versions prior …9.8
- CVE-2026-40353wger is a free, open-source workout and fitness manager. In …5.4
- CVE-2026-40354Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1…6.3
- CVE-2026-40355In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL …7.5
- CVE-2026-40356In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an inte…7.5
- CVE-2026-40357Deserialization of untrusted data in Microsoft Office ShareP…8.8
- CVE-2026-40358Heap-based buffer overflow in Microsoft Office allows an una…8.4
Are you affected by CVE-2026-40352?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
