CVE-2025-50674

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
22/08/2025
Last modified:
12/09/2025

Description

An issue was discovered in the changePassword method in file /usr/share/php/openmediavault/system/user.inc in OpenMediaVault 7.4.17 allowing local authenticated attackers to escalate privileges to root.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openmediavault:openmediavault:7.4.17:*:*:*:*:*:*:*