PT-2026-7625 · Pacom · Pacom Unison Client

Published

2026-02-11

·

Updated

2026-02-11

·

CVE-2025-65480

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pacom Unison Client version 5.13.1
Description An issue exists in Pacom Unison Client where authenticated users can inject malicious scripts into Report Templates. These scripts are executed when specific script conditions are met, potentially leading to Remote Code Execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-65480

Affected Products

Pacom Unison Client