PT-2025-46539 · Altair · Altair Grid Engine
Published
2025-11-11
·
Updated
2025-11-11
·
CVE-2025-40760
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Altair Grid Engine versions prior to 2026.0.0
Description
The software does not properly handle error messages, leading to the disclosure of sensitive password hash information during user authentication requests. This could allow a local attacker to extract password hashes for privileged accounts, potentially enabling offline brute-force attacks. The API endpoint involved in this issue is the user authentication request process. The vulnerable information is the
password hash.Recommendations
Update to version 2026.0.0 or later.
Fix
Generation of Error Message Containing Sensitive Information
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Altair Grid Engine