CVE-2025-58052 is a high-severity access control bypass vulnerability affecting Galette membership management software versions 0.9.6 through 1.1.9. A malicious insider or compromised group manager account can exploit this flaw to gain unauthorized access and make changes, bypassing intended role-based restrictions. The CVSS score is 8.1 (High), indicating a network-exploitable vulnerability with low attack complexity that can lead to high confidentiality and integrity impacts. While no public exploits or active exploitation have been observed, and community discussion is minimal, the FAUCET Risk Score of 87/100 suggests a significant risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.0CPE matchmatch criteria | cpe:2.3:a:galette:galette:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.