Not a potential bug. Is a confirmed bug. I fixed it.
326-bit password. CB saves the password wrong.
Generally, people won't use such strong passwords. But it is a good practice to store your passwords securely in some offline computer, behind another personal password.
Do note that Joomla itself does not have this bug that CB has.
My users also see an error appearing when changing password. It blinks up above password field when saving the modified profile.
After that, the confirmation appears, suggesting that password has been changed. Login with new password works however, but the word 'error' is confusing.