CVE-2026-52809: Wrong Token Lifetime For Password Resetcve-2026-52809-wrong-token-lifetime-for-password-reset
Generating an activation token instead of a password reset token may grant an attacker a much longer window to exploit hijacked reset links. Password reset tokens should have a distinct, shorter lifetime than generic account activation tokens.