# CVE-2025-26486

## Summary

- **CVE ID:** CVE-2025-26486
- **Severity:** MEDIUM
- **CVSS Score:** 6 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N)
- **CWE:** CWE-327, CWE-916, CWE-328, CWE-760
- **Published:** Mar 19, 2025
- **Last Modified:** Mar 13, 2026

## Description

Broken or Risky Cryptographic Algorithm, Use of Password Hash 
With Insufficient Computational Effort, Use of Weak Hash, Use of a 
One-Way Hash with a Predictable Salt vulnerabilities in Beta80 "Life 1st Identity Manager"
enable an attacker with access to
password hashes
to bruteforce user passwords or find a collision to ultimately while attempting to gain access to a target application that uses "Life 1st Identity Manager" as a service for authentication.
This issue affects Life 1st: 1.5.2.14234.

## Affected Products

- Beta80 — Life 1st (1.5.2.14234)

## References

- [CNA](https://www.cvcn.gov.it/cvcn/cve/CVE-2025-26486)
- [CNA](https://euvd.enisa.europa.eu/vulnerability/CVE-2025-26486)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.12%
- **EPSS Percentile:** 1.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._