AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2025-13909

MEDIUM · CVSS 4.3 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The vulnerability arises from inadequate validation of authentication requests, compromising tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This flaw can lead to unauthorized access to personally identifiable information across different tenants, posing significant privacy risks and potential regulatory non-compliance. Organizations utilizing these authentication methods should prioritize remediation to protect user data and maintain compliance.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-13909
Severity
MEDIUM
CVSS
4.3
EPSS
0.21%

Original NVD Description

The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead to the exposure of personally identifiable information. Successful exploitation allows an attacker to disclose personally identifiable information of users in different tenants, resulting in privacy violations and potential regulatory non-compliance. This may include unauthorized access to user details such as mobile numbers.

Related CVEs

Other vulnerabilities affecting the same vendor(s)