CVE-2025-26486: BETA80 Life 1st

Medium severity, CVSS 6.0. EPSS: 0.1% chance of exploitation in the next 30 days.

Broken or Risky Cryptographic Algorithm, Use of Password Hash With Insufficient Computational Effort, Use of Weak Hash, Use of a One-Way Hash with a Predictable Salt vulnerabilities in Beta80 "Life 1st Identity Manager" enable an attacker with access to password hashes to bruteforce user passwords or find a collision to ultimately while attempting to gain access to a target application that uses "Life 1st Identity Manager" as a service for authentication. This issue affects Life 1st: 1.5.2.14234.

Affected products

  • BETA80 Life 1st: version 1.5.2.14234 only

Published 2025-03-19. Last modified 2026-06-17.