PT-2026-21798 · Unknown · Eventsentry
Vulncheck
·
Published
2026-02-24
·
Updated
2026-02-25
·
CVE-2026-24443
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EventSentry versions prior to 6.0.1.20
Description
EventSentry has a flaw where passwords can be changed without verifying the current password through the account management functionality within the Web Reports interface. An attacker gaining access to an authenticated user session can modify the account password without knowing the original credentials. This allows for persistent account takeover, potentially leading to privilege escalation if administrative accounts are compromised.
Recommendations
Update EventSentry to version 6.0.1.20 or later.
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eventsentry