CVE-2025-26138
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Mar 18, 2025
Updated: Apr 1, 2025
CWE ID 284
Summary
CVE-2025-26138 is a vulnerability affecting Systemic Risk Value version 2.8.0 or below. The issue lies in the application's GetFile.aspx function in the /RiskValue/GroupingEntities/Controls directory. An improper access control issue has been identified, allowing unauthorized users to download files by predicting and manipulating numerical ID parameters in the URL. This can result in unintended file access, leading to potential data exposure or unauthorized modifications.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.