CVE-2025-67806: Medium severity Sage Sage DPW vulnerability
Published Apr 1, 2026
·Updated
The login mechanism of Sage DPW 202106004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 202106000. On-premise administrators can toggle this behavior in newer versions.
Affected Software
2 affected components
Sage Sage DPW<2021_06_000
Sagedpw Sage Dpw=2025_06_004
Event History
Apr 1, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·04:23 PM
DescriptionSeverityWeaknessAffected Software