CVE-2025-41090

Severity CVSS v4.0:
HIGH
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
28/10/2025
Last modified:
30/10/2025

Description

microCLAUDIA in v3.2.0 and prior has an improper access control vulnerability.<br /> <br /> This flaw allows an authenticated user to perform unauthorized actions on other organizations&amp;#39; systems by sending direct API requests. To do so, the attacker can use organization identifiers obtained through a compromised endpoint or deduced manually.<br /> <br /> This vulnerability allows access between tenants, enabling an attacker to list and manage remote assets, uninstall agents, and even delete vaccines configurations.