CVE-2026-64822

Source
https://cve.org/CVERecord?id=CVE-2026-64822
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64822.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64822
Published
2026-07-21T20:28:03Z
Modified
2026-10-08T02:51:33Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
djangoSIGE 1.10 User Enumeration via ForgotPasswordView
Details

djangoSIGE through 1.10 (commit a6fe7e8) contains a user enumeration vulnerability in ForgotPasswordView within djangosige/apps/login/views.py that allows unauthenticated attackers to identify valid accounts by observing distinct error messages returned by the password reset endpoint. Attackers can submit arbitrary usernames or email addresses to the POST login/esqueceu/ endpoint and distinguish between existing and non-existing accounts based on observable discrepancies in the application's responses.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-203"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64822.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "last_affected": "1.10"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/thiagopena/djangoSIGE

Affected ranges

Type
GIT
Repo
https://github.com/thiagopena/djangoSIGE
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected

Affected versions

0.*
0.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64822.json"