CVE-2025-27926
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Mar 10, 2025
CWE ID 276
Summary
CVE-2025-27926 is a vulnerability affecting Nintex Automation versions 5.6 and 5.7 before 5.8. The issue lies in the readability of passwords contained within the K2 SmartForms Designer folder's configuration files (web.config). Unauthorized users can access these passwords, posing a security risk. This vulnerability could potentially enable unauthorized access or data breaches. Users are advised to upgrade to Nintex Automation version 5.8 to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Automation