CVE-2025-9467

MEDIUM

Vaadin <7.7.47, <8.28.1, <14.13.0, <23.6.1, <24.7 - Auth Bypass

Title source: llm
STIX 2.1

Description

When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass the upload validation. Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include: Product version Vaadin 7.0.0 - 7.7.47 Vaadin 8.0.0 - 8.28.1 Vaadin 14.0.0 - 14.13.0 Vaadin 23.0.0 - 23.6.1 Vaadin 24.0.0 - 24.7.6 Mitigation Upgrade to 7.7.48 Upgrade to 8.28.2 Upgrade to 14.13.1 Upgrade to 23.6.2 Upgrade to 24.7.7 or newer Please note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 14, 23, 24 version. Artifacts     Maven coordinatesVulnerable versionsFixed versioncom.vaadin:vaadin-server 7.0.0 - 7.7.47 ≥7.7.48 com.vaadin:vaadin-server 8.0.0 - 8.28.1 ≥8.28.2 com.vaadin:vaadin 14.0.0 - 14.13.0 ≥14.13.1 com.vaadin:vaadin23.0.0 - 23.6.1 ≥23.6.2 com.vaadin:vaadin24.0.0 - 24.7.6 ≥24.7.7com.vaadin:vaadin-upload-flow 2.0.0 - 14.13.0 ≥14.13.1 com.vaadin:vaadin-upload-flow 23.0.0 - 23.6.1 ≥23.6.2 com.vaadin:vaadin-upload-flow 24.0.0 - 24.7.6 ≥24.7.7

References (1)

Core 1
Core References

Scores

CVSS v4 5.3
EPSS 0.0036
EPSS Percentile 27.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:L/U:Green

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (9)
com.vaadin/vaadin-server 7.0.0 - 7.7.48Maven
vaadin/framework 7.0.0 - 7.7.47
vaadin/framework 8.0.0 - 8.28.1
vaadin/vaadin 14.0.0 - 14.13.0
vaadin/vaadin 23.0.0 - 23.6.1
vaadin/vaadin 24.0.0 - 24.7.6
vaadin/vaadin-upload-flow 14.0.0 - 14.13.0
vaadin/vaadin-upload-flow 23.0.0 - 23.6.1
vaadin/vaadin-upload-flow 24.0.0 - 24.7.6
Published Sep 04, 2025
Tracked Since Feb 18, 2026