CVE-2025-60949
Severity CVSS v4.0:
CRITICAL
Type:
CWE-200
Information Leak / Disclosure
Publication date:
23/03/2026
Last modified:
24/03/2026
Description
Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked secrets. Fixed in 8.1.0 alpha.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
9.10
Severity 3.x
CRITICAL



