What is CVE-2026-64822?
djangoSIGE through version 1.10 (commit a6fe7e8) contains a user enumeration vulnerability in the password reset function, allowing unauthenticated attackers to identify valid accounts via distinct error messages. Upgrading to the latest version is recommended to mitigate this issue.
Azərbaycanca: djangoSIGE v1.10-a qədər (commit a6fe7e8) versiyalarında Forg parol bərpa funksiyasında istifadəçi adı sadalama zəifliyi aşkarlanıb. Təsdiqlənməmiş şəxslər sistemin qaytardığı fərqli xəta mesajları vasitəsilə etibarlı hesabları müəyyən edə bilər. Təhlükəsizlik üçün sistemi ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of djangoSIGE are affected by CVE-2026-64822?
djangoSIGE through version 1.10, up to commit a6fe7e8, is affected by this vulnerability.
How can one mitigate the CVE-2026-64822 vulnerability?
Upgrading to the latest version is recommended to mitigate this issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.