CVE-2025-5997
Incorrect Use of Privileged APIs vulnerability in Beamsec PhishPro allows Privilege Abuse.This issue affects PhishPro: before 7.5.4.2.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.38%
- CWE
- CWE-648
- Published
- 2025-07-28
- Last modified
- 2026-06-05
Affected products
- Beamsec PhishPro
Weakness type
Related vulnerabilities
- CVE-2026-63727 — Anchore Enterprise Privilege Escalation via User Management API
- CVE-2026-54424 — An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a...
- CVE-2026-11877 — Missing Authorization Vulnerability in OpenText Access Manager
- CVE-2026-9560 — Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows...
- CVE-2026-41225 — iControl REST vulnerability
- CVE-2026-41386 — OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes
- CVE-2026-41329 — OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalation
- CVE-2026-35669 — OpenClaw < 2026.3.25 - Privilege Escalation via Gateway Plugin HTTP Authentication Scope