Account Enumeration Vulnerability in Sage DPW by Sage
CVE-2025-67807

4.7MEDIUM

Key Information:

Vendor

Sage

Status
Vendor
CVE Published:
1 April 2026

What is CVE-2025-67807?

The login mechanism of Sage DPW before version 2021_06_000 exposes a security flaw that enables on-premise administrators to distinguish between valid and invalid usernames. This behavior can lead to account enumeration, where unauthorized users may exploit this weakness to identify existing accounts, potentially increasing the risk of targeted attacks. Newer versions provide a toggle feature for administrators to manage this vulnerability effectively.

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.