CVE-2025-10226

Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
10/09/2025
Last modified:
19/12/2025

Description

Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier on Windows and Linux allows a remote attacker to escalate privileges, execute arbitrary code, or cause denial-of-service via exploitation of multiple known CVEs present in PostgreSQL v10.x, which are resolved in PostgreSQL 17.4.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:axxonsoft:axxon_one:*:*:*:*:*:*:*:* 2.0.8 (including)
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*