CVE-2025-50503
8.8Touch · Touch Lebanon Mobile App
A vulnerability in the Touch Lebanon Mobile App password reset workflow allows an unauthenticated attacker to bypass the OTP mechanism and gain unauthorized account access.
Executive summary
A critical authentication bypass vulnerability in the Touch Lebanon Mobile App 2.20.2 allows unauthorized attackers to reset user passwords and compromise accounts.
Vulnerability
This is an authentication bypass vulnerability affecting the password reset workflow. An unauthenticated attacker can manipulate the reset process to circumvent OTP verification and gain full access to a target account.
Business impact
The ability for an unauthenticated user to reset any account password poses a severe risk to data confidentiality and integrity. Given the 8.8 CVSS score, this vulnerability could lead to widespread unauthorized access to sensitive user information, potential identity theft, and significant reputational damage to the service provider.
Remediation
Immediate Action: Users and administrators should check the official Touch portal for security updates and apply the latest version of the mobile application as soon as it is released.
Proactive Monitoring: Security teams should review application access logs for unusual patterns in password reset requests or high volumes of failed authentication attempts from specific IP addresses.
Compensating Controls: If an update is not immediately available, users should enable additional account-level protections if provided by the platform, and organizations should monitor for suspicious account activity linked to mobile application traffic.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists via the researcher's disclosure on GitHub.
Analyst recommendation
This vulnerability represents a high-risk security flaw that directly enables unauthorized account takeover. Organizations and individual users must prioritize updating the Touch Lebanon Mobile App to the latest available version once the vendor provides a patch. Constant vigilance regarding account security and monitoring for unauthorized access attempts remains essential until the remediation is applied.