CVE-2025-27008
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-27008 is a Missing Authorization vulnerability that affects NotFound Unlimited Timeline. This issue enables unauthorized access to functionality that is not properly constrained by Access Control Lists (ACLs). As a result, attackers can bypass security restrictions and gain unintended access to certain features or information within the affected system. This vulnerability can potentially impact all versions of NotFound Unlimited Timeline, from the earliest to the latest versions. Organizations using this software are advised to apply the necessary patches or updates as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.