CVE-2025-26372

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Feb 12, 2025
Updated: Mar 3, 2025
CWE ID 862

Summary

CVE-2025-26372 is a vulnerability affecting Q-Free MaxTime versions 2.11.0 and below. This issue, classified as a CWE-862 "Missing Authorization" flaw, enables authenticated low-privileged attackers to manipulate user group membership. By constructing carefully crafted HTTP requests, they can successfully remove users from groups within the system. This vulnerability poses a significant risk to the integrity of user access control within impacted implementations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Q-Free Maxtime

Affected Vendors

  • Nozomi Networks