AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-64400

MEDIUM · CVSS 4.1 EPSS 0.19%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-12-18 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.1. See the original NVD description below for full technical details.

CVE
CVE-2025-64400
Severity
MEDIUM
CVSS
4.1
EPSS
0.19%

Original NVD Description

Control Panel provides an API for pre-registering into an enrollment and organization prior to a user's first login. The API for creating users checks that the account requesting a user creation has `edit` on the enrollment-level user directory, but is missing a separate check that the enrollment editor has access (or belongs to) the organization that they are adding a user to.