PT-2026-21798 · Unknown · Eventsentry

Vulncheck

·

Published

2026-02-24

·

Updated

2026-02-25

·

CVE-2026-24443

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EventSentry versions prior to 6.0.1.20
Description EventSentry has a flaw where passwords can be changed without verifying the current password through the account management functionality within the Web Reports interface. An attacker gaining access to an authenticated user session can modify the account password without knowing the original credentials. This allows for persistent account takeover, potentially leading to privilege escalation if administrative accounts are compromised.
Recommendations Update EventSentry to version 6.0.1.20 or later.

Fix

LPE

Weakness Enumeration

Related Identifiers

CVE-2026-24443

Affected Products

Eventsentry