PT-2026-6794 · Deepaudit · Deepaudit

Ez-Lbz

·

Published

2026-02-06

·

Updated

2026-02-28

·

CVE-2026-25729

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions DeepAudit versions prior to 3.0.5
Description An improper access control issue exists in DeepAudit versions 3.0.4 and earlier. The /api/v1/users/ API endpoint allows any authenticated user to enumerate all users within the system. This allows retrieval of sensitive information such as email addresses, phone numbers, full names, and role information. The vulnerable parameter is not specified.
Recommendations Update DeepAudit to version 3.0.5 or later.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-25729
GHSA-VMMM-48W2-Q56Q

Affected Products

Deepaudit