# CVE-2025-27906

## Summary

- **CVE ID:** CVE-2025-27906
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **CWE:** CWE-548
- **Published:** Oct 14, 2025
- **Last Modified:** Mar 13, 2026

## Description

IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an application URL. Application files and folders are visible in the browser to a user; however, the contents of the files cannot be read obtained or modified.

## Affected Products

- IBM — Content Navigator (3.0.11)
- IBM — Content Navigator (3.0.15)
- IBM — Content Navigator (3.1.0)
- IBM — Content Navigator (3.2.0)

## References

- [CNA](https://www.ibm.com/support/pages/node/7247854)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.29%
- **EPSS Percentile:** 20.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-12._