CVE-2025-26960

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 25, 2025
CWE ID 862

Summary

CVE-2025-26960 is a new vulnerability affecting the Small Package Quotes – Unishippers Edition software from enituretechnology. This issue involves a missing authorization control, allowing unauthorized access to certain functionalities. The security flaw arises due to incorrectly configured access control security levels. This vulnerability has been identified in versions 2.4.9 and below, putting potentially many users at risk. Unauthorized users may be able to exploit this issue to gain unauthorized access and potentially cause damage or steal sensitive information. Organizations using this software are urged to update to the latest version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share