CVE-2025-41090
Severity CVSS v4.0:
HIGH
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
28/10/2025
Last modified:
30/10/2025
Description
microCLAUDIA in v3.2.0 and prior has an improper access control vulnerability.<br />
<br />
This flaw allows an authenticated user to perform unauthorized actions on other organizations&#39; systems by sending direct API requests. To do so, the attacker can use organization identifiers obtained through a compromised endpoint or deduced manually.<br />
<br />
This vulnerability allows access between tenants, enabling an attacker to list and manage remote assets, uninstall agents, and even delete vaccines configurations.
Impact
Base Score 4.0
7.60
Severity 4.0
HIGH



