
CVE-2026-31881 Runtipi is a personal homeserver orchestrator. Prior to 4.8.0, an unauthenticated attacker can reset the operator (admin) password when a password-reset request is ac… https://www.cve.org/CVERecord?id=CVE-2026-31881
Post summary
The CVE allows an unauthenticated attacker to reset the operator/admin password before Runtipi version 4.8.0. No PoC, exploit, patch, or active exploitation details are provided.
