CVE-2025-35042
Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
22/09/2025
Last modified:
19/12/2025
Description
Airship AI Acropolis includes a default administrative account that uses the same credentials on every installation. Instances of Airship AI that do not change this account password are vulnerable to a remote attacker logging in and gaining the privileges of this account. Fixed in 10.2.35, 11.0.21, and 11.1.9.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:airship.ai:acropolis:*:*:*:*:*:*:*:* | 10.2.35 (excluding) | |
| cpe:2.3:a:airship.ai:acropolis:*:*:*:*:*:*:*:* | 11.0.0 (including) | 11.0.21 (excluding) |
| cpe:2.3:a:airship.ai:acropolis:*:*:*:*:*:*:*:* | 11.1.0 (including) | 11.1.9 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



