Apache Fineract Weak Password Requirements Vulnerability

Vulnerability

A vulnerability exists in Apache Fineract versions prior to 1.10.1, related to weak password requirements. This issue could lead to inadequate password strength, potentially allowing for easier unauthorized access. The vulnerability has been addressed in version 1.11.0, and users are encouraged to upgrade to version 1.13.0, the latest release.

Impact

The weak password policy could allow users to create easily guessable passwords, increasing the risk of unauthorized access.

Remediation

Users should upgrade to Apache Fineract version 1.13.0 or later.

Added: Dec 12, 2025, 10:21 AM
Updated: Dec 12, 2025, 3:33 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
5.0
exploitability
6.6
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.