CVE-2025-26953
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Apr 15, 2025
Updated: Apr 16, 2025
CWE ID 862
Summary
CVE-2025-26953 is a Missing Authorization vulnerability that affects JetMenu, a component used in various applications. The issue resides in JetMenu versions from n/a to 2.4.9, where functionality is not properly constrained by Access Control Lists (ACLs), enabling unauthorized access. Attackers can exploit this vulnerability to gain access to restricted features and potentially cause harm to targeted systems. Organizations using JetMenu are advised to update to the latest patched version to mitigate this security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.