CVE-2025-26700

MEDIUM

RoboForm Password Manager <9.7.4 - Auth Bypass

Title source: llm
STIX 2.1

Description

Authentication bypass using an alternate path or channel issue exists in ”RoboForm Password Manager" App for Android versions prior to 9.7.4, which may allow an attacker with access to a device where the application is installed to bypass the lock screen and obtain sensitive information.

References (2)

Core 2
Core References

Scores

CVSS v3 5.2
EPSS 0.0024
EPSS Percentile 15.3%
Attack Vector PHYSICAL
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-288
Status published
Products (1)
Siber Systems, Inc./RoboForm Password Manager prior to 9.7.4
Published Feb 17, 2025
Tracked Since Feb 18, 2026