CVE-2025-58402

HIGH

CGM CLININET < 2025.ms4 - Unauthenticated Authorization Bypass via MessageID Parameter

Title source: llm
STIX 2.1

Description

The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks. By modifying the parameter in the GET request, an attacker can access messages and attachments belonging to other users.

References (2)

Core 2
Core References
Various Sources third-party-advisory
https://cert.pl/en/posts/2026/03/CVE-2025-10350/

Scores

CVSS v3 7.5
EPSS 0.0022
EPSS Percentile 11.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
cgm/clininet < 2025.ms4
Published Mar 02, 2026
Tracked Since Mar 02, 2026