---
id: CVE-2026-16751
title: >-
  Authorization Bypass in the emergency recovery approval component in Ente
  Technologies Ente Museum Server allows an authenticated attacker configured as
  a victim's emergency contact to bypass the configured recovery waiting period
  and ta…
summary: >-
  Authorization Bypass in the emergency recovery approval component in Ente
  Technologies Ente Museum Server allows an authenticated attacker configured as
  a victim's emergency contact to bypass the configured recovery waiting period
  and ta…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-863
  - CWE-778
vendor: Ente
product: Museum Server
affected:
  - museum_server <= 2.0.34
published: '2026-07-29'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T14:17:06.840'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16751'
references:
  - url: >-
      https://github.com/ente/ente/commit/4789ae67368c1f9ba7eb1a0e2c0588e4a9a55746
    label: cret@cert.org
  - url: 'https://github.com/ente/ente/tree/v2.0.34'
    label: cret@cert.org
  - url: 'https://vokecyber.com/blog/cve-2026-16751-ente-emergency-recovery-bypass'
    label: cret@cert.org
  - url: >-
      https://vokecyber.com/research/cve-2026-16751-ente-emergency-recovery-bypass
    label: cret@cert.org
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-07-30T13:39:12.881743Z'
epss: 0.00295
epssPercentile: 0.22368
ingestedAt: '2026-09-23T14:25:29.789Z'
---

## Overview

Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum Server allows an authenticated attacker configured as a victim's emergency contact to bypass the configured recovery waiting period and take over the victim's account via a crafted `approve-recovery` API request.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
