Junglewise Threat Intelligence

CVE-2025-67806: The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing ac

CVE-2025-67806 · Severity: low · CVSS 3.7 · Published 2026-04-01

Executive brief

Sage DPW, an HR and payroll software solution, contains a flaw in its login system that reveals whether a username is valid or not. By observing different error messages for existing versus non-existent accounts, an unauthorized person could compile a list of valid employee usernames. This information can be used to launch more targeted cyberattacks, such as password guessing or phishing campaigns.

Technical details

An observable response discrepancy (CWE-204) exists in the authentication handler of Sage DPW. The application returns different feedback or error messages depending on whether a submitted username exists in the database. A remote, unauthenticated attacker can exploit this behavior by programmatically submitting lists of potential usernames and analyzing the responses to identify valid accounts. This vulnerability was addressed in version 2021_06_004, where on-premise administrators were also given the ability to toggle this behavior. Sage DPW Cloud is reportedly unaffected.

Affected products

  • Sage DPW Prior to 2021_06_004

Timeline

  • 2026-03-24: disclosed: Vulnerability details shared via Pastebin by Limes Security.
  • 2026-04-01: advisory: CVE published.

References

Related threats