PT-2025-48821 · Canonical · Maas
Jacopo Rota
·
Published
2025-12-03
·
Updated
2025-12-08
·
CVE-2025-7044
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MAAS (affected versions not specified)
Description
An improper input validation issue exists in the user websocket handler. An authenticated, unprivileged attacker can intercept a
user.update websocket request and modify the is superuser property to true. The server does not properly validate this input, allowing the attacker to gain administrative privileges and full control over the MAAS deployment. The vulnerable component is the websocket handler responsible for processing user.update requests.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Maas