CVE-2025-57644

CRITICAL

Accela Automation Platform 22.2.3.0.230103 - RCE & Arbitrary File Write via Test Script

Title source: llm
STIX 2.1

Description

Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can execute arbitrary Java code on the server, resulting in remote code execution. In addition, improper input validation allows for arbitrary file write and server-side request forgery (SSRF), enabling interaction with internal or external systems. Successful exploitation can lead to full server compromise, unauthorized access to sensitive data, and further network exploitation.

References (2)

Core 2

Scores

CVSS v3 9.1
EPSS 0.0069
EPSS Percentile 48.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20 CWE-22 CWE-918 CWE-94
Status published
Products (1)
accela/automation_platform 22.2.3.0.230103
Published Sep 19, 2025
Tracked Since Feb 18, 2026