CVE-2025-12812 is an SQL Injection vulnerability affecting Delinea Inc. Cloud Suite and Privileged Access Service, allowing an authenticated attacker to manipulate SQL queries. With a CVSS score of 5.3 (MEDIUM), this vulnerability has a low attack complexity and requires low privileges, potentially leading to limited confidentiality and integrity impacts. There is currently no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage, indicating a low immediate threat level. The issue is remediated in Cloud Suite version 25.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Delinea Inc. | Cloud Suite And Privileged Access Service | 23.1.2 and earlierCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.