CVE-2025-27568

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Apr 15, 2025
Updated: Apr 16, 2025
CWE ID 639

Summary

CVE-2025-27568 is a newly disclosed vulnerability that allows unauthenticated attackers to retrieve users' email addresses by using their knowledge of a username. This issue arises due to insufficient access controls, leading to the inadvertent sending of password reset emails in response to unsolicited requests. An attacker, without requiring any authentication or authorization, can exploit this vulnerability to gain access to a large number of email addresses, which can be used for various malicious purposes such as phishing or spamming. Organizations using the affected system are advised to apply the necessary patches or updates as soon as possible to mitigate the risk of potential email address compromises.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share