# CVE-2025-9210

## Summary

- **CVE ID:** CVE-2025-9210
- **Severity:** HIGH
- **CVSS Score:** 8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
- **CWE:** CWE-347
- **Published:** Aug 18, 2026
- **Last Modified:** Aug 18, 2026

## Description

Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via tampering with JWTs

## Affected Products

- Otalio — Ship Property Management System (0)

## References

- [CNA](https://www.otalio.com/solutions/)
- [CNA](https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2026/MNDT-2026-0023.md)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.15%
- **EPSS Percentile:** 5.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._