CVE-2026-25654Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate user authorization when processing password reset requests. This could allow an authenticated remote attacker to bypass authorization checks, leading to the ability to reset the password of any arbitrary user account.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-04-14); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-14: 3Mentions · 2026-04-21: 1Mentions · 2026-04-30: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-14: 3Technical Details · 2026-04-30: 104-1404-2104-30
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-143
Disclosure2Patch1
2026-04-211
General1
2026-04-301
Disclosure1
Full discourse5 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-297|CVE-2026-25654] Siemens SINEC NMS Improper Authentication Privilege Escalation Vulnerability (CVSS 8.8; Credit: Rocco Calvi (@TecR0c) with TecSecurity) https://www.zerodayinitiative.com/advisories/ZDI-26-297/

    Post summary

    The advisory announces CVE-2026-25654 as an Improper Authentication Privilege Escalation flaw in Siemens SINEC NMS with a CVSS of 8.8, but does not provide exploit, patch, or mitigation details.

    010301.2K
    5.5K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Siemens ❗ CVE-2026-27668 ❗ CVE-2026-25654 ❗ CVE-2026-24032 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-siemens-5/ https://t.co/xaUvGrjHyI

    Post summary

    Three Siemens product CVEs are listed with a link for more information, but no additional details on exploitation, patches, or technical specifics are provided.

    0000098
    6.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25654 Authentication Bypass in SINEC NMS Versions Below 4.0 SP3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25654 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    A newly disclosed authentication bypass vulnerability (CVE-2026-25654) affecting SINEC NMS below version 4.0 SP3 is highlighted with a link to Vulmon, but no proof‑of‑concept, exploit code, patch, or exploitation activity is mentioned.

    0000035
    4.0K followersView on X
  • dbugs@ptdbugs
    Disclosure

    CVE: CVE-2026-25654 PT ID: PT-2026-32608 Vendor: Siemens Product: SINEC NMS CVSS: 8.8 Credits: n/a Description: A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate user authorization when processing password reset requests. This could allow an authenticated remote attacker to bypass authorization checks, leading to the ability to reset the password of any arbitrary user account. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-32608 • https://cert-portal.siemens.com/productcert/html/ssa-605717.html #dbugs_vuln

    Post summary

    CVE‑2026‑25654 is a disclosed vulnerability in Siemens SINEC NMS that lets an authenticated remote attacker reset any user password by bypassing authorization checks; no PoC, exploit, or patch is mentioned.

    00000157
    797 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25654: HIGH] Critical cyber security alert! A vulnerability in SINEC NMS (All versions &lt; V4.0 SP3) allows attackers to reset any user's password. Update to SP3 immediately to stay secure.#cve,CVE-2026-25654,#cybersecurity https://cvefind.com/CVE-2026-25654

    Post summary

    The advisory warns of a high‑severity flaw in SINEC NMS versions prior to SP3 that allows attackers to reset any user's password, recommending an upgrade to SP3 to mitigate the risk.

    0000055
    620 followersView on X

Explore more