CVE-2025-59683

HIGH

Pexip Infinity 15.0-38.0 - Incorrect Authorization in Secure Scheduler for Exchange

Title source: llm
STIX 2.1

Description

Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to a denial of service.

References (1)

Core 1
Core References

Scores

CVSS v3 8.2
EPSS 0.0029
EPSS Percentile 20.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
pexip/pexip_infinity 15 - 38.1
Published Dec 25, 2025
Tracked Since Feb 18, 2026