CVE-2025-26347

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 12, 2025
CWE ID 306

Summary

CVE-2025-26347 is a vulnerability affecting Q-Free MaxTime versions 2.11.0 and below. It is classified as a CWE-306 "Missing Authentication for Critical Function" issue. An attacker can exploit this flaw by crafting malicious HTTP requests to edit user permissions without authentication. This vulnerability poses a significant risk, as it enables unauthenticated remote attackers to manipulate user access levels, potentially leading to unauthorized access or other malicious activities.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Q-Free Maxtime

Affected Vendors

  • Nozomi Networks