CVE-2026-6217: Information Disclosure in Pik Online Software's Portal
Published Sep 4, 2026
·Updated
Use of a One-Way hash without a salt vulnerability in Pik Online Software Solutions Inc. Pik Online Portal allows Cryptanalysis.
This issue affects Pik Online Portal: through 3.5.1.
Affected Software
1 affected component
Pik Online Software Solutions Inc. Pik Online Portal<=3.5.1
Event History
Sep 4, 2026
CVE Published
via MITRE·07:27 AM
Data Sourced
via MITRE·07:27 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access and interaction are required to exploit this issue?
The vector indicates network-based exploitation with low attack complexity, but the attacker must have low-level privileges and requires user interaction.
2
Which deployments are known to be affected?
Pik Online Portal versions through 3.5.1 are affected. The available information does not state whether any particular default configuration is required.
3
What is the likely security impact?
The issue can expose confidential information and may allow limited integrity impact. No availability impact is indicated.