CVE-2025-27008

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 15, 2025
Updated: Apr 16, 2025
CWE ID 862

Summary

CVE-2025-27008 is a Missing Authorization vulnerability that affects NotFound Unlimited Timeline. This issue enables unauthorized access to functionality that is not properly constrained by Access Control Lists (ACLs). As a result, attackers can bypass security restrictions and gain unintended access to certain features or information within the affected system. This vulnerability can potentially impact all versions of NotFound Unlimited Timeline, from the earliest to the latest versions. Organizations using this software are advised to apply the necessary patches or updates as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share