CVE-2026-6217
Use of a One-Way hash without a salt vulnerability in Pik Online Software Solutions Inc. Pik Online Portal allows Cryptanalysis. This issue affects Pik Online Portal: through 3.5.1.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
- EPSS probability
- 0.11%
- CWE
- CWE-759
- Published
- 2026-09-04
- Last modified
- 2026-09-04
Affected products
- Pik Online Software Solutions Inc. Pik Online Portal
Weakness type
Related vulnerabilities
- CVE-2025-36271 — IBM Integrated Analytics System (IIAS) is affected by a predictable salt vulnerability in Magneto component
- CVE-2026-57263 — A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password...
- CVE-2025-15631 — Weak Credential Storage in TP-Link Omada Devices
- CVE-2025-15544 — Weak Credential Protection During TP-Link Omada Device Adoption
- CVE-2026-45787 — electerm's encrypt method not safe enough
- CVE-2026-45027 — WeGIA: Use of Weak Password Hashing Algorithm (SHA-256, no salt) in html/login.php
- CVE-2026-9370 — ulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConfig.java getSecretKeySaltGenerator hash predictable salt
- CVE-2025-36253 — Multiple Vulnerabilities in IBM Concert Software.