CWE-620: Unverified Password Change
When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.
87 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-4322 — Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
- CVE-2024-20419 — A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauth
- CVE-2025-1107 — Unverified password change vulnerability in Janto
- CVE-2024-33699 — The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers t
- CVE-2025-4558 — WormHole Tech GPM - Unverified Password Change
- CVE-2025-2253 — IMITHEMES Listing <= 3.3 - Unauthenticated Privilege Escalation via Unverified Password Reset
- CVE-2025-10159 — An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wi
- CVE-2024-37998 — A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base syste
- CVE-2024-48887 — A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to c
- CVE-2025-14751 — Unverified Password Change in Weintek cMT X Series HMI EasyWeb Service
- CVE-2025-67719 — Ibexa User Bundle is missing password change validation
- CVE-2025-62425 — Matrix Authentication Service account password can be changed using an authenticated session without supplying the current password
- CVE-2026-15964 — Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Change
- CVE-2025-9286 — Appy Pie Connect for WooCommerce <= 1.1.2 - Missing Authorization to Unauthenticated Privilege Escalation via reset_user_password
- CVE-2026-12692 — Improper Authentication in Vimesoft's Enterprise Video Platform
- CVE-2025-13148 — IBM Aspera Orchestrator Unverified Password Change
- CVE-2026-77644 — Critical Bypass Access Control Vulnerability Reported for Windchill Risk and Reliability (WRR) Enterprise Edition
- CVE-2026-5386 — KMW CCTV Security Cameras Unverified Password Change
- CVE-2025-5482 — Sunshine Photo Cart <= 3.4.11 - Authenticated (Subscriber+) Privilege Escalation
- CVE-2025-3607 — Frontend Login and Registration Blocks <= 1.0.8 - Authenticated (Subscriber+) Privilege Escalation via Password Reset
Recently published
- CVE-2026-86260 — sfturing hosp_order Password Recovery CommonUserController.java modifyPassWord unverified password change
- CVE-2026-85591 — phpMyFAQ before 4.1.8 Authentication Bypass via Unverified Password Change
- CVE-2026-77644 — Critical Bypass Access Control Vulnerability Reported for Windchill Risk and Reliability (WRR) Enterprise Edition
- CVE-2026-76633 — WeGIA < 3.9.2 Authorization Bypass Password Change via alterarSenha
- CVE-2026-73292 — Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
- CVE-2026-17599 — Nexus Repository 3 - Unverified Onboarding State on change-admin-password Endpoint
- CVE-2026-15964 — Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Change
- CVE-2026-12692 — Improper Authentication in Vimesoft's Enterprise Video Platform
- CVE-2026-56305 — Capgo - Authentication Bypass in Password Change via Missing Current Password Validation
- CVE-2026-54801 — A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst
- CVE-2026-44733 — OpenProject: Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirements
- CVE-2025-71328 — Flowise - Unverified Password Change via Account Settings
- CVE-2025-71337 — Flowise - Unverified Email Change via Account Profile Endpoint
- CVE-2026-5386 — KMW CCTV Security Cameras Unverified Password Change
- CVE-2026-9249 — Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the pr
- CVE-2026-8327 — Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass.
- CVE-2026-42084 — OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
- CVE-2026-40588 — blueprintUE: Authenticated Password Change Does Not Verify Current Password
- CVE-2019-25653 — Navicat for Oracle 12.1.15 Password Field Denial of Service
- CVE-2025-70082 — Lantronix EDS3000PS Unverified Password Change