CVE-2025-15586

CRITICAL

OGP-Website <52f865a - Auth Bypass

Title source: llm
STIX 2.1

Description

OGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw which if exploited can result in authentication bypass without knowledge of the victim account's password.

Scores

CVSS v4 10.0
EPSS 0.0012
EPSS Percentile 30.9%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-287
Status published
Products (1)
OpenGamePanel/OGP-Website < 52f865a4fba763594453068acf8fa9e3fc38d663
Published Feb 19, 2026
Tracked Since Feb 19, 2026