CVE-2025-62645
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token with administrative privileges for the entire platform via the createToken GraphQL mutation.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.9
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.67%
- CWE
- CWE-266
- Published
- 2025-10-17
- Last modified
- 2026-03-12
Affected products
- Restaurant Brands International assistant platform
Weakness type
Related vulnerabilities
- CVE-2026-81805 — WordPress SiteSkite plugin <= 2.1.5 - Privilege Escalation vulnerability
- CVE-2026-15140 — A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP)....
- CVE-2026-86804 — seakee CPA-Manager-Plus HTTP handler.go CPAResource improper authorization
- CVE-2026-77654 — Local Privilege Escalation via Misconfigured Sudoers Entry in Horizon Security Analyzer
- CVE-2026-85400 — TYPO3 CMS - Missing Authorization in lowlevel commands
- CVE-2026-81792 — WordPress Product Catalog Enquiry for WooCommerce by MultiVendorX plugin <= 6.1.4 - Privilege Escalation vulnerability
- CVE-2026-86516 — elenavanengelenmaslova mocknest-serverless AWS GitHub OIDC Deployment Helper Script github-oidc-role.yaml privileges management
- CVE-2026-86512 — java-json-tools json-patch Copy Move Operations CopyOperation.java MoveOperation.apply access control