PT-2025-48411 · Orionsec · Orion-Ops

Sh7Err03

·

Published

2025-12-01

·

Updated

2025-12-01

·

CVE-2025-13807

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions orionsec orion-ops versions up to 5925824997a3109651bbde07460958a7be249ed1
Description A flaw exists in orionsec orion-ops that leads to improper authorization. This issue is located within the MachineKeyController function in the MachineKeyController.java file of the API component. The issue can be exploited remotely. The exploit is publicly available. The vendor was notified but did not respond.
Recommendations Versions up to 5925824997a3109651bbde07460958a7be249ed1 should be updated. As a temporary workaround, consider restricting access to the MachineKeyController function until a patch is available.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-13807

Affected Products

Orion-Ops