CVE-2025-59784

HIGH

2N Access Commander <3.4.1 - Log Pollution

Title source: llm
STIX 2.1

Description

2N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be included in the logs without prior validation or sanitisation. This vulnerability can only be exploited after authenticating with administrator privileges.

Scores

CVSS v3 7.2
EPSS 0.0006
EPSS Percentile 18.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-117
Status published
Products (1)
2n/access_commander < 3.4.2
Published Mar 04, 2026
Tracked Since Mar 04, 2026