CVE-2025-57644 is a critical vulnerability affecting Accela Automation Platform 22.2.3.0.230103, stemming from multiple flaws in its Test Script feature. An authenticated administrative user can achieve remote code execution (RCE) via arbitrary Java code execution, arbitrary file write, and server-side request forgery (SSRF). This allows for full server compromise, unauthorized data access, and network exploitation. With a CVSS score of 9.1 (CRITICAL), the attack vector is network-based with low complexity, requiring high privileges but no user interaction. While not currently in the KEV catalog or having public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered significant community discussion with 10 mentions, indicating growing awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
22.2.3.0.230103CPE matchmatch criteria | cpe:2.3:a:accela:automation_platform:22.2.3.0.230103:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.