CVE-2025-26486

CVSS 3.1 Score 6 of 10 (medium)

Details

Published Mar 19, 2025
CWE ID 328
CWE ID 916
CWE ID 760
CWE ID 327

Summary

CVE-2025-26486 is a vulnerability affecting Life 1st Identity Manager version 1.5.2.14234. The issue involves the use of a broken or risky cryptographic algorithm, insufficient computational effort in password hashing, and a weak hash, creating an opportunity for an attacker to bruteforce user passwords or find a collision. This can ultimately grant unauthorized access to the target application.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share