CVE-2025-26486
CVSS 3.1 Score 6 of 10 (medium)
Details
Published Mar 19, 2025
CWE ID 328
CWE ID 916
CWE ID 760
CWE ID 327
Summary
CVE-2025-26486 is a vulnerability affecting Life 1st Identity Manager version 1.5.2.14234. The issue involves the use of a broken or risky cryptographic algorithm, insufficient computational effort in password hashing, and a weak hash, creating an opportunity for an attacker to bruteforce user passwords or find a collision. This can ultimately grant unauthorized access to the target application.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.