CVE-2025-49825
Teleport allows remote authentication bypass
Record summary
CVE-2025-49825 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 are vulnerable to remote authentication bypass. At time of posting, there is no available open-source patch.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 18, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
teleportBrowse gravitational / teleport | CVE List | <= 17.5.1 | affected |
| <= 0.0.0-20250616162021-79b2f26125a1 | affected | ||
github.com/gravitational/teleportBrowse Go / github.com/gravitational/teleport | GitHub Advisory | 17.0.0 to < 17.5.2 · Fixed in 17.5.2 | affected |
| 16.0.0 to < 16.5.12 · Fixed in 16.5.12 | affected | ||
| 15.0.0 to < 15.5.3 · Fixed in 15.5.3 | affected | ||
| 14.0.0 to < 14.4.1 · Fixed in 14.4.1 | affected | ||
| 13.0.0 to < 13.4.27 · Fixed in 13.4.27 | affected | ||
| 0.0.11 to < 12.4.35 · Fixed in 12.4.35 | affected | ||
| Through 0.0.0-20250616162021-79b2f26125a1 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALTeleport - Authentication BypassCVSS 9.8
Teleport versions prior to 17.5.2 are vulnerable to a remote authentication bypass vulnerability. This issue allows attackers to gain unauthorized access to affected systems.
Impact
Attackers can bypass authentication mechanisms to gain unauthorized access to Teleport systems, potentially compromising protected infrastructure and sensitive resources.
Remediation
Upgrade Teleport to version 17.5.2, 16.5.12, 15.5.3, 14.4.1, 13.4.27, or 12.4.35 depending on your version branch.
Source: ProjectDiscovery