CVE-2025-59785

HIGH

2N Access Commander <3.4.2 - Auth Bypass

Title source: llm
STIX 2.1

Description

Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password policy for backup file encryption. This vulnerability can only be exploited after authenticating with administrator privileges.

Scores

CVSS v3 7.2
EPSS 0.0005
EPSS Percentile 14.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-1286
Status published
Products (1)
2n/access_commander < 3.5
Published Mar 04, 2026
Tracked Since Mar 04, 2026