CVE-2025-65742

HIGH

Newgen OmniDocs v11.0 - Info Disclosure

Title source: llm

Description

An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to obtain sensitive information and execute a full account takeover via a crafted API request.

Exploits (1)

nomisec WRITEUP
by CBx216 · poc
https://github.com/CBx216/CVE-Newgen-Software-Advisories

Scores

CVSS v3 8.2
EPSS 0.0007
EPSS Percentile 21.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Details

CWE
CWE-862
Status published
Products (1)
newgensoft/omnidocs 11.0
Published Dec 15, 2025
Tracked Since Feb 18, 2026