← Back to CVE List

CVE-2025-26138

Published: 2025-03-18T17:15Z
Last Modified: 2025-04-01T20:37Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Systemic Risk Value <=2.8.0 is vulnerable to improper access control in /RiskValue/GroupingEntities/Controls/GetFile.aspx?ID=. Uploaded files are accessible via a predictable numerical ID parameter, allowing unauthorized users to increment or decrement the ID to access and download files they do not have permission to view. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt