CVE-2025-58052

HIGH

Galette < 1.2.0 - Authenticated Incorrect Authorization via Group Manager Role

Title source: llm
STIX 2.1

Description

Galette is a membership management web application for non profit organizations. Starting in version 0.9.6 and prior to version 1.2.0, attackers with group manager role can bypass intended restrictions allowing unauthorized access and changes despite role-based controls. Since it requires privileged access initially, exploitation is restricted to malicious insiders or compromised group managers accounts. Version 1.2.0 fixes the issue.

References (1)

Core 1
Core References

Scores

CVSS v3 8.1
EPSS 0.0027
EPSS Percentile 18.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
galette/galette < 1.2.0
Published Dec 19, 2025
Tracked Since Feb 18, 2026