216.73.216.223

CVE-2025-49652

· Published 09/06/2025 18:15 · Modified 09/06/2025 18:15

Labels: CVE-2025-49652 2025-06-096f8de1f0-f67e-45a6-b68f-98777fdb759cCVE-2025-49652CWE-306

Essential information

Published
09/06/2025 18:15
Modified
09/06/2025 18:15
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
6f8de1f0-f67e-45a6-b68f-98777fdb759c
NVD
View on NVD

Affected products (CPE)

ProductCPE
lablup / backendai cpe:2.3:a:lablup:backendai:*:*:*:*:*:*:*:*

References