Account Enumeration Vulnerability in Sage DPW by Sage
CVE-2025-67806

3.7LOW

Key Information:

Vendor

Sage

Status
Vendor
CVE Published:
1 April 2026

What is CVE-2025-67806?

The login mechanism in the Sage DPW software prior to version 2021_06_000 reveals distinct responses for both valid and invalid usernames. This behavior creates opportunities for attackers to enumerate existing accounts by repeatedly attempting logins. While on-premise administrators can mitigate this risk in newer versions, it remains a critical concern for earlier releases, potentially exposing user accounts to unauthorized access.

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.