CVE-2025-9572

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows low-privileged users to access sensitive information that they shouldn't be able to see, due to weak security checks in the GraphQL API. It occurs because the API fails to properly enforce user permissions, unlike the more secure REST API, making it easier for attackers to bypass restrictions.

Technical Description

n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
Confidentiality ImpactLow
Integrity ImpactNone
Availability ImpactNone
ScopeChanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$672($500-$1K)
Vendor Response
Grade APatched in 0 days

Quick Information

Published

Feb 27, 2026

about 1 month ago

Last Modified

Feb 27, 2026

about 1 month ago