User Enumeration Vulnerability in djangoSIGE Product by Americooo
CVE-2026-64822
Key Information:
- Vendor
Thiagopena
- Status
- Vendor
- CVE Published:
- 21 July 2026
Badges
What is CVE-2026-64822?
The djangoSIGE product, up to version 1.10, contains a vulnerability that allows unauthenticated attackers to exploit the ForgotPasswordView functionality. By interacting with the password reset endpoint, attackers can submit arbitrary usernames or email addresses and determine if they correspond to valid accounts based on the distinct error messages received. This flaw can potentially lead to greater security risks including targeted attacks, as the ability to enumerate user accounts opens the door for further exploitation.
Affected Version(s)
djangoSIGE 0 <= 1.10
djangoSIGE 0 <= 1.10
djangoSIGE 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
