CVE-2025-26372
CVSS 3.1 Score 8.1 of 10 (high)
Details
Published Feb 12, 2025
Updated: Mar 3, 2025
CWE ID 862
Summary
CVE-2025-26372 is a vulnerability affecting Q-Free MaxTime versions 2.11.0 and below. This issue, classified as a CWE-862 "Missing Authorization" flaw, enables authenticated low-privileged attackers to manipulate user group membership. By constructing carefully crafted HTTP requests, they can successfully remove users from groups within the system. This vulnerability poses a significant risk to the integrity of user access control within impacted implementations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Q-Free Maxtime
Affected Vendors
- Nozomi Networks