nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-10226 CVE-2025-10226
CRITICAL
PostgreSQL Upgrade from v10 to v17.4 in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier to Address Multiple Vulnerabilities
Record summary
CVE-2025-10226 has a selected CVSS score of 9.3 (critical).
Description
Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier on Windows and Linux allows a remote attacker to escalate privileges, execute arbitrary code, or cause denial-of-service via exploitation of multiple known CVEs present in PostgreSQL v10.x, which are resolved in PostgreSQL 17.4.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 10, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
AxxonOne C-WerkBrowse AxxonSoft / AxxonOne C-WerkDefault status: unaffected | CVE List | Through 2.0.8 | affected |
References
3axxonsoft.com
https://www.axxonsoft.com/legal/axxonsoft-vulnerability-disclosure-policy/security-advisories postgresql.org
https://www.postgresql.org/docs/release