CVE-2026-25197
Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
03/04/2026
Last modified:
03/04/2026
Description
A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
9.10
Severity 3.x
CRITICAL



