PT-2025-38543 · Accela · Accela Automation Platform

Anvarkh

·

Published

2025-09-19

·

Updated

2025-10-17

·

CVE-2025-57644

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Accela Automation Platform version 22.2.3.0.230103
Description Accela Automation Platform contains multiple issues within the Test Script feature. An authenticated administrative user can execute arbitrary Java code on the server, potentially leading to remote code execution. Improper input validation allows for arbitrary file write and server-side request forgery (SSRF), enabling interaction with internal or external systems. Successful exploitation could result in full server compromise and unauthorized access to sensitive data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Path traversal

SSRF

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-57644

Affected Products

Accela Automation Platform