Ad

CVE-2026-24443

HIGH CVSS 4.0: 8.6 EPSS 0.02%
Updated Feb 26, 2026
Netikus
Parameter Value
CVSS 8.6 (HIGH)
Affected Versions before 6.0.1.20
Fixed In 6.0.1.20
Type CWE-620
Vendor Netikus
Public PoC No

EventSentry versions prior to 6.0.1.20 contain an unverified password change vulnerability in the account management functionality of the Web Reports interface. The password change mechanism does not require validation of the current password before allowing a new password to be set. An attacker who gains temporary access to an authenticated user session can change the account password without knowledge of the original credentials.

This enables persistent account takeover and, if administrative accounts are affected, may result in privilege escalation.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v4.0

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Netikus Eventsentry
cpe:2.3:a:netikus:eventsentry:*:*:*:*:*:*:*:*
6.0.1.20