CVE-2026-24468General

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campaign and tests. Starting in version 1.11.0 and prior to version 2.0.13, the /api/reset endpoint behaves differently depending on whether the supplied username exists in the system. When a non-existent email is provided in the login parameter, the endpoint returns an HTTP 400 response (Bad Request). When a valid email is supplied, the endpoint responds with HTTP 200. This difference in server responses creates an observable discrepancy that allows an attacker to reliably determine which emails are registered in the application. By automating requests with a list of possible email addresses, an attacker can quickly build a list of valid accounts without any authentication. The endpoint should return a consistent response regardless of whether the username exists in order to prevent account enumeration. Version 2.0.13 fixes this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-204

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-04-21)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-20: 1Mentions · 2026-04-21: 2Patch / Workaround · 2026-04-21: 1Technical Details · 2026-04-20: 104-2004-21
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-201
General1
2026-04-212
Disclosure1General1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-24468 OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campaign and tests. Starting in version 1.11.0 and … https://www.cve.org/CVERecord?id=CVE-2026-24468 ----- Traducción: CVE-2026-24468 Ope… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑24468 for OpenAEV, noting a newer release (v1.11.0) that presumably contains the fix, but provides no further exploit or technical details.

    0000024
    72 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-24468 OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campaign and tests. Starting in version 1.11.0 and … https://www.cve.org/CVERecord?id=CVE-2026-24468

    Post summary

    The text only references the CVE identifier and a brief mention of the affected platform, without any evidence of exploitation, mitigation, or detailed technical information.

    00000137
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-24468 User Enumeration via Inconsistent API Responses in OpenAEV Before 2.0.13 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24468 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The tweet announces CVE-2026-24468, highlighting a user‑enumeration flaw in OpenAEV versions before 2.0.13, and links to further details via Vulmon, but does not provide a PoC, exploit code, patch information, or evidence of active exploitation.

    0000047
    4.0K followersView on X

Explore more