CVE-2025-9822
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
- EPSS probability
- 0.24%
- CWE
- CWE-283
- Published
- 2025-09-03
- Last modified
- 2026-03-12
Affected products
- Mautic Mautic
- Mautic Mautic
- Mautic Mautic
Weakness type
Related vulnerabilities
- CVE-2026-84386 — A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7,...
- CVE-2026-85781 — Unverified access point ownership in Amazon EFS CSI Driver
- CVE-2026-9745 — Vulnerabilities exists in IBM Netezza Software
- CVE-2026-54467 — On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on...
- CVE-2026-15599 — Arbitrary Process Termination in TÜBİTAK BİLGEM's pardus-domain-joiner
- CVE-2026-44707 — Chatwoot: Pre-Account Takeover via OAuth on Unconfirmed Accounts
- CVE-2026-44562 — Open WebUI: Model Import Overwrites Any Model Without Ownership Check
- CVE-2026-40337 — Sentry kernel has incomplete ownership check for IRQ line manipulation