Skip to content
vaultocean
Field
criticalAccess Control
4 min read2026-06-12

IDOR to full account takeover via predictable UUIDv1

AN

anon

security researcher · vault ocean

Time-based UUIDs leaked creation order; enumerating them exposed password-reset tokens for any user.

UUIDv1 encodes a timestamp and node id, so tokens issued close together are highly predictable. By harvesting a few reset tokens and interpolating, an attacker could mint a valid token for any account. Fix: use UUIDv4 (CSPRNG) for anything security-sensitive, and bind reset tokens to the user + a server-side secret.

You read it — record it

sign in to record this and keep your streak alive

Reading earns +25ƒ and keeps your streak alive.

Discussion · 0

Loading…

Sign in to leave a comment.

AN

Written by

anon

Security researcher · Vault Ocean contributor