CVE-2025-49652

CRITICAL

BackendAI < 25.15.6 - Unauthenticated User Registration Bypass

Title source: llm
STIX 2.1

Description

Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0023
EPSS Percentile 45.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (2)
Lablup/BackendAI
pypi/backend.ai 0 - 25.15.6PyPI
Published Jun 09, 2025
Tracked Since Feb 18, 2026