CVE-2025-13808

HIGH

orionsec orion-ops - Incorrect Privilege Assignment in User Profile Handler

Title source: llm
STIX 2.1

Description

A flaw has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this vulnerability is the function update of the file orion-ops-api/orion-ops-web/src/main/java/cn/orionsec/ops/controller/UserController.java of the component User Profile Handler. This manipulation of the argument ID causes improper authorization. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.333818
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.333818
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.692068

Scores

CVSS v3 7.3
EPSS 0.0041
EPSS Percentile 32.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-266 CWE-285
Status published
Products (1)
orionsec/orion-ops < 2025-08-01
Published Dec 01, 2025
Tracked Since Feb 18, 2026