CVE-2025-27568
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2025-27568 is a newly disclosed vulnerability that allows unauthenticated attackers to retrieve users' email addresses by using their knowledge of a username. This issue arises due to insufficient access controls, leading to the inadvertent sending of password reset emails in response to unsolicited requests. An attacker, without requiring any authentication or authorization, can exploit this vulnerability to gain access to a large number of email addresses, which can be used for various malicious purposes such as phishing or spamming. Organizations using the affected system are advised to apply the necessary patches or updates as soon as possible to mitigate the risk of potential email address compromises.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cloud Applications