Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-67796

Опубликовано: 04 мая 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

IKUS Rdiffweb before 2.10.5 has an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6.

EPSS

Процентиль: 16%
0.00245
Низкий

8.1 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 8.1
debian
4 месяца назад

IKUS Rdiffweb before 2.10.5 has an improper authorization flaw that al ...

CVSS3: 8.1
github
4 месяца назад

IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users

EPSS

Процентиль: 16%
0.00245
Низкий

8.1 High

CVSS3

Дефекты

CWE-284