CVE-2025-26485 – Beta80 Life 1st Identity Manager: Authentication Information Exposure

The following table lists the changes that have been made to the
CVE-2025-26485 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by a6d3dc9e-0591-4a13-bce7-0f5b31ff6158

    Mar. 19, 2025

    Action Type Old Value New Value
    Added Description The Exposure of Sensitive Information to an Unauthorized Actor
    vulnerability impacting Beta80 Life 1st Identity Manager allows User
    Enumeration using Authentication Rest APIs. Affected: Life 1st version
    1.5.2.14234. Different error messages are returned to failed authentication attempts
    in case of the usage of a wrong password or a non existent user.

    This issue affects Life 1st: 1.5.2.14234.

    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
    Added CWE CWE-200
    Added Reference https://www.cvcn.gov.it/cvcn/cve/CVE-2025-26485
Share the Post:

Related Posts