Cyber & AI intelligence
Wasteland.
Briefs indexed3056
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-19218 2026-10-08

CVE-2026-19218: Critical Password Recovery Flaw in AKIN Software MyRezzta

"A critical-severity (CVSS 9.1) weakness in MyRezzta's forgotten-password mechanism lets attackers abuse password recovery over the network without authentication."

A critical-severity (CVSS 9.1) weakness in MyRezzta's forgotten-password mechanism lets attackers abuse password recovery over the network without authentication.

What Is It

CVE-2026-19218 is a weak password recovery mechanism vulnerability (CWE-640) in MyRezzta, a product from AKIN Software Computer Import-Export Industry and Trade Co. Ltd. The CVE description says the flaw "allows Password Recovery Exploitation." The record does not publish further technical details.

USOM, Turkey's national CERT, reported the issue ([email protected]). It was published to NVD on 2026-10-08. Its NVD status is "Received," which means NVD has not yet done its own analysis.

Why It Matters

USOM rates the issue 9.1 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N:

Abuse of a password recovery flow can lead to account takeover. These scores mean an unauthenticated remote attacker could read and change data that the application protects.

Exploitation status: CVE-2026-19218 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The supplied sources do not confirm any active exploitation, and there is no CISA-mandated required action or due date.

What's Vulnerable

Vendor Product Affected Versions
AKIN Software Computer Import-Export Industry and Trade Co. Ltd. MyRezzta 2.06.03 up to (but not including) 2.07.01

The record treats versions outside that range as unaffected. NVD has not published any CPE entries yet.

Patch Status

The record gives only an affected range that ends before 2.07.01. It does not name 2.07.01 as a fixed release or describe a patch. Version 2.07.01 and later fall outside the listed vulnerable range, but no vendor advisory in the supplied sources confirms that the upgrade fixes the flaw. Organizations running MyRezzta 2.06.03 or a later 2.06.x/2.07.00 release should check with AKIN Software and read USOM advisory TR-26-1274 to confirm which release fixes the issue before relying on an upgrade.

The supplied record has no vendor advisory and no list of workarounds. Since NVD analysis is still pending, watch for updates to the record.

Sources