CVE-2026-55445
A critical flaw in Qinglong allows an unauthenticated attacker to reset administrator credentials by sending a PUT request to /open/user/init. The vulnerability exists in versions before 2.20.1 and can be fixed by upgrading to 2.20.1 or later.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Qinglong timed task management platform, versions prior to 2.20.1. Typical users are administrators of the platform.
Real-world impact
An attacker could reset the admin password and take full control of the platform without authentication.
Why this severity
The CVSS score of 9.3 reflects the high impact of credential reset (high confidentiality impact) combined with low attack complexity and no authentication required.
What to do about it
- 011. Upgrade Qinglong to version 2.20.1 or later.
- 022. Restart the Qinglong service to apply the update.
NVD-referenced vendor advisory
Timeline
- Jul 16, 2026 · 18d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 18, 2026 · 15d agoAdvisory updatedThe NVD record was last revised.
- Jul 19, 2026 · 15d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.