PT-2025-46539 · Altair · Altair Grid Engine

Published

2025-11-11

·

Updated

2025-11-11

·

CVE-2025-40760

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Altair Grid Engine versions prior to 2026.0.0
Description The software does not properly handle error messages, leading to the disclosure of sensitive password hash information during user authentication requests. This could allow a local attacker to extract password hashes for privileged accounts, potentially enabling offline brute-force attacks. The API endpoint involved in this issue is the user authentication request process. The vulnerable information is the password hash.
Recommendations Update to version 2026.0.0 or later.

Fix

Generation of Error Message Containing Sensitive Information

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2026-05804
BDU:2026-05805
CVE-2025-40760

Affected Products

Altair Grid Engine