Description
The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000. On-premise administrators can toggle this behavior in newer versions.
Published: 2026-04-01
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Sage DPW application returns distinguishable responses for valid and invalid login usernames. This behavioural difference allows an attacker to probe the system and confirm whether a specific account exists. The weakness aligns with CWE‑203 (Information Exposure through Data or Metadata) and CWE‑204 (Information Exposure through Attribute or Unintended Information Leak). Account enumeration can be leveraged for targeted social‑engineering, credential‑guessing, or to locate privileged accounts, thereby increasing the adversary’s success probability.

Affected Systems

All Sage DPW installations that run a build before the 2021_06_000 release are affected. In those older deployments the enumeration behaviour cannot be disabled. Newer releases introduced a configuration option that lets on‑premise administrators suppress the distinct login responses. The publicly listed CPE refers to the 2025_06_004 build, which includes this toggle feature.

Risk and Exploitability

The CVSS score of 3.7 places the issue in the low‑severity range, and the EPSS score of less than 1% indicates a very low probability of exploitation as of the current data. It is not listed in CISA’s KEV catalog. Exploitation requires access to the web‑based login page, a function that is generally reachable by anyone who can reach the Sage DPW instance. It is inferred that the likely attack vector is remote via the HTTP interface. Because the impact is limited to identifying user existence, the overall risk is modest, though the vulnerability remains actionable for security teams that need to protect user information.

Generated by OpenCVE AI on May 10, 2026 at 17:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Sage DPW to a release that includes the ability to suppress distinct login responses, such as the 2025_06_004 build or later.
  • If an upgrade cannot be performed immediately, log into the administrative console and enable the option that disables separate responses for valid and invalid usernames, thereby eliminating the enumeration path.
  • Restrict network access to the login page—apply firewall rules or segment the network to reduce exposure to automated enumeration attempts.

Generated by OpenCVE AI on May 10, 2026 at 17:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 10 May 2026 17:45:00 +0000

Type Values Removed Values Added
Title Account Enumeration via Username Disclosure in Sage DPW

Sun, 10 May 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-204

Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
Title Account Enumeration via Username Disclosure in Sage DPW

Wed, 08 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Title Account Enumeration via Distinct Login Responses in Sage DPW
Weaknesses CWE-200

Tue, 07 Apr 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Sagedpw
Sagedpw sage Dpw
Weaknesses CWE-203
CPEs cpe:2.3:a:sagedpw:sage_dpw:2025_06_004:*:*:*:*:*:*:*
Vendors & Products Sagedpw
Sagedpw sage Dpw

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Title Account Enumeration via Distinct Login Responses in Sage DPW
First Time appeared Sage
Sage dpw
Weaknesses CWE-200
Vendors & Products Sage
Sage dpw

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000. On-premise administrators can toggle this behavior in newer versions.
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AC:H/AV:N/A:N/C:L/I:N/PR:N/S:U/UI:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-05-10T14:00:24.179Z

Reserved: 2025-12-12T00:00:00.000Z

Link: CVE-2025-67806

cve-icon Vulnrichment

Updated: 2026-04-01T15:53:38.923Z

cve-icon NVD

Status : Modified

Published: 2026-04-01T16:23:48.323

Modified: 2026-05-10T14:16:46.130

Link: CVE-2025-67806

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-10T17:30:16Z

Weaknesses