What is CVE-2026-25427?
CVE-2026-25427 is a "Subscriber Broken Access Control" vulnerability found in eRoom versions 1.7.1 and earlier. This flaw could allow low-privileged subscribers to gain unauthorized access to restricted functionalities. Users of eRoom are advised to immediately update to the latest version.
Azərbaycanca: CVE-2026-25427 eRoom platformunun 1.7.1 və daha əvvəlki versiyalarında aşkarlanmış "Subscriber Broken Access Control" zəifliyidir. Bu zəiflik aşağı səviyyəli istifadəçilərə (subscriber) daha yüksək səlahiyyətlər tələb edən funksiyalara icazəsiz giriş imkanı verə bilər. eRoom istifadəçiləri dərhal ən son versiyaya yeniləmə etməlidirlər.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which platform is affected by CVE-2026-25427?
This vulnerability affects eRoom platform versions 1.7.1 and earlier.
What should eRoom users do to protect against CVE-2026-25427?
Users should immediately update to the latest version of eRoom.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.