CVE-2025-40897

An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restriction not being properly enforced for users with view-only privileges. An authenticated user with view-only privileges for the Threat Intelligence functionality can perform administrative actions on it, altering the rules configuration, and/or affecting their availability.
Configurations

No configuration.

History

No history.

Information

Published : 2026-04-15 09:16

Updated : 2026-06-17 09:22


NVD link : CVE-2025-40897

Mitre link : CVE-2025-40897

CVE.ORG link : CVE-2025-40897


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization