PT-2025-44091 · Unknown · Microclaudia
Published
2025-10-28
·
Updated
2025-11-10
·
CVE-2025-41090
CVSS v4.0
7.6
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
microCLAUDIA versions prior to 3.2.0
Description
An improper access control issue exists in microCLAUDIA. An authenticated user can perform unauthorized actions on other organizations' systems by sending direct API requests. Attackers can leverage organization identifiers obtained through compromised endpoints or manual deduction to exploit this flaw. This allows cross-tenant access, enabling actions such as listing and managing remote assets, uninstalling agents, and deleting vaccine configurations. The affected API endpoints are not specified. The vulnerable parameter is the organization identifier.
Recommendations
Update to a version newer than 3.2.0.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Microclaudia