CVE-2025-26137

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 18, 2025
Updated: Apr 1, 2025
CWE ID 98

Summary

CVE-2025-26137 is a newly identified vulnerability affecting Systemic Risk Value version 2.8.0 and below. This issue permits an unauthenticated attacker to execute Local File Inclusion attacks through the GetFile.aspx endpoint. By supplying a crafted file path, the attacker can read arbitrary system files, potentially exposing sensitive information. System administrators are urged to upgrade to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share