LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-25197

CVE-2026-25197 - Vulnerability Analysis

CriticalCVSS: 9.1

Last Updated: April 3, 2026

Generic Product - Broken Access Control

Published: April 3, 2026Updated: April 3, 2026PoC AvailableRemote Exploitable

Overview

A specific product contains a broken access control vulnerability caused by insufficient authorization checks on user ID in API calls, letting authenticated users access other user profiles by modifying the ID, exploit requires authentication.

Severity & Score

Severity: Critical
CVSS Score: 9.1

Impact

Authenticated users can access other user profiles, leading to unauthorized data exposure.

Mitigation

Update to the latest version with proper authorization checks.

Details

CVE ID
CVE-2026-25197
Severity
Critical
CVSS Score
9.1
Type
broken_access_control
Status
new

CWE

  • CWE-639

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N