CVE-2025-26818
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2025-26818 is a recently disclosed vulnerability affecting Netwrix Password Secure versions up to 9.2. This issue permits attackers to execute command injection attacks, potentially granting unauthorized access to sensitive password data. An attacker can exploit this vulnerability by sending specially crafted input to the Netwrix Password Secure server, enabling them to execute arbitrary commands with administrative privileges. Successful exploitation could result in data theft, unauthorized system modifications, or other significant security consequences. Users are strongly encouraged to update to the latest version of Netwrix Password Secure to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Netwrix