# CVE-2025-27580

## Summary

- **CVE ID:** CVE-2025-27580
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-335
- **Published:** Apr 23, 2025
- **Last Modified:** Mar 13, 2026

## Description

NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that depend on username, time, and the fixed 7Dl9#dj- string) and thus allows unauthenticated users with a Common Access Card (CAC) to escalate privileges and compromise any account, including administrators.

## Affected Products

- NIH — BRICS (0)

## References

- [CNA](https://github.com/brics-dev/brics)
- [CNA](https://brics.cit.nih.gov)
- [CNA](https://github.com/brics-dev/brics/blob/26bc6bb627a9a60e6c6a8a8c29735ae98c2e2679/core/src/main/java/gov/nih/tbi/CoreConstants.java#L38)
- [CNA](https://github.com/brics-dev/brics/blob/26bc6bb627a9a60e6c6a8a8c29735ae98c2e2679/service/src/main/java/gov/nih/tbi/account/service/complex/AccountManagerImpl.java#L725-L732)
- [CNA](https://github.com/RoseHacks/Vulnerability.Research/blob/main/CVE-2025-27580/README.md)
- [CNA](https://bugculture.io/CVE-2025-27580/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.68%
- **EPSS Percentile:** 50.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._