CVE-2023-4003: Oneidentity Password Manager

Medium severity, CVSS 6.8. EPSS: 0.5% chance of exploitation in the next 30 days.

One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM through an unspecified method. CWE-250: Execution with Unnecessary Privileges.

Affected products

  • Oneidentity Password Manager: from 5.9.7.1, before 5.11.2 (fixed in 5.11.2); from 5.12.0, before 5.12.2 (fixed in 5.12.2)

Published 2023-09-27. Last modified 2026-06-17.