CVE-2025-27929

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Apr 15, 2025
Updated: Apr 16, 2025
CWE ID 639

Summary

CVE-2025-27929 is a newly disclosed vulnerability that allows unauthenticated attackers to retrieve a complete list of users associated with arbitrary accounts. This issue can potentially be exploited to conduct targeted social engineering attacks or brute force attacks against those users. The impact of this vulnerability extends beyond the compromised account, as the attacker can gain valuable information for further exploitation. Organizations using the affected system are advised to apply the available patch as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share