CVE-2026-57263
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password feature in the affected products stores the password as an unsalted SHA-256 hash. This could allow an attacker who has obtained the project file to perform efficient offline dictionary or brute-force attacks against the unsalted hash.
Scoring
- Severity
- HIGH
- CVSS base score
- 7
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.08%
- CWE
- CWE-759
- Published
- 2026-08-11
- Last modified
- 2026-08-11
Affected products
- Siemens LOGO! Soft Comfort
Weakness type
Related vulnerabilities
- CVE-2026-6217 — Information Disclosure in Pik Online Software's Portal
- CVE-2025-36271 — IBM Integrated Analytics System (IIAS) is affected by a predictable salt vulnerability in Magneto component
- CVE-2025-15631 — Weak Credential Storage in TP-Link Omada Devices
- CVE-2025-15544 — Weak Credential Protection During TP-Link Omada Device Adoption
- CVE-2026-45787 — electerm's encrypt method not safe enough
- CVE-2026-45027 — WeGIA: Use of Weak Password Hashing Algorithm (SHA-256, no salt) in html/login.php
- CVE-2026-9370 — ulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConfig.java getSecretKeySaltGenerator hash predictable salt
- CVE-2025-36253 — Multiple Vulnerabilities in IBM Concert Software.