
🚨 CVE-2024-5386: Account Hijacking via Password Re... Trivial privilege escalation in lunary-ai lets 'viewers' harvest password reset tokens with a single request, enabling f... https://zerodaysignal.com/vulnerability/CVE-2024-5386 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
CVE-2024-5386 exposes a privilege‑escalation flaw in lunary‑ai that enables harvesting password reset tokens for account hijacking; a PoC link is provided but no exploit code, patch, or evidence of active exploitation is mentioned.
