CVE-2025-8853
Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use it to log into the system as that user.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.69%
- CWE
- CWE-290
- Published
- 2025-08-11
- Last modified
- 2026-03-12
Affected products
- 2100 Technology Official Document Management System
- 2100 Technology Official Document Management System
- 2100 Technology Official Document Management System
Weakness type
Related vulnerabilities
- CVE-2026-88011 — Traefik: ForwardAuth identity spoofing via dot-form header alias
- CVE-2026-66674 — WordPress Simple Cloudflare Turnstile plugin <= 1.42.1 - Captcha Bypass vulnerability
- CVE-2026-88879 — Traefik before v2.11.56 Identity Spoofing via Header Alias
- CVE-2026-82563 — Softish C6 Ear Camera and EarVision Android Application Authentication bypass by spoofing
- CVE-2026-82530 — IP2Location Country Blocker < 2.45.0 Access Control Bypass via X-Real-IP Header
- CVE-2026-62759 — Windows Netlogon Spoofing Vulnerability
- CVE-2026-86478 — In JetBrains YouTrack before 2025.3.161254,...
- CVE-2026-84186 — Incorrect access control in PrestaShop