CVE-2025-26347
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Feb 12, 2025
CWE ID 306
Summary
CVE-2025-26347 is a vulnerability affecting Q-Free MaxTime versions 2.11.0 and below. It is classified as a CWE-306 "Missing Authentication for Critical Function" issue. An attacker can exploit this flaw by crafting malicious HTTP requests to edit user permissions without authentication. This vulnerability poses a significant risk, as it enables unauthenticated remote attackers to manipulate user access levels, potentially leading to unauthorized access or other malicious activities.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Q-Free Maxtime
Affected Vendors
- Nozomi Networks