What is CVE-2025-14779?
CVE-2025-14779 affects the Secret Type Management REST API, where access controls are not properly enforced during deletion. The cascade logic fails to isolate organizations, causing secrets across all orgs to be deleted when a secret type is removed. Immediate patching is required.
Azərbaycanca: CVE-2025-14779 “Secret Type Management REST API”-də aşkarlanıb: secret type silinərkən təşkilat sərhədləri düzgün tətbiq olunmur. Bu, kaskad silmə nəticəsində bütün təşkilatlardakı əlaqəli secret-lərin icazəsiz silinməsinə yol aça bilər. Təcili yamaq tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ1
What is the main impact of CVE-2025-14779?
This vulnerability in the Secret Type Management REST API allows unauthorized deletion of associated secrets across all organizations, not just the intended one, because organization boundaries are not properly enforced during cascade deletion when a secret type is removed.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.