CVE Explorer
CVE-2026-24443
EventSentry versions prior to 6.0.1.20 contain an unverified password change vulnerability in the account management functionality of the Web Reports interface. The password change mechanism does not require validation of the current password before allowing a new password to be set. An attacker who gains temporary access to an authenticated user session can change the account password without knowledge of the original credentials. This enables persistent account takeover and, if administrative
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"EventSentry","vendor":"NETIKUS.NET ltd","versions":[{"lessThan":"6.0.1.20","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:33fcf507c0d4950077b2c6605706d3d573baba8d5a2686d6a0315a25118523fd · sha256:1f278980b9c668a7… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.6,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"H…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:33fcf507c0d4950077b2c6605706d3d573baba8d5a2686d6a0315a25118523fd · sha256:1f278980b9c668a7… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-620","description":"CWE-620 Unverified Password Change","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:33fcf507c0d4950077b2c6605706d3d573baba8d5a2686d6a0315a25118523fd · sha256:1f278980b9c668a7… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["release-notes","patch"],"url":"https://www.eventsentry.com/downloads/version-history"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:33fcf507c0d4950077b2c6605706d3d573baba8d5a2686d6a0315a25118523fd · sha256:1f278980b9c668a7… · /containers/cna/references/0
{"tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/eventsentry-web-reports-unverified-password-change"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:33fcf507c0d4950077b2c6605706d3d573baba8d5a2686d6a0315a25118523fd · sha256:1f278980b9c668a7… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.