CVE-2026-25197 describes an Insecure Direct Object Reference (IDOR) vulnerability where authenticated users can access other user profiles by manipulating ID numbers in API calls; the specific affected product is not detailed in the available information. Rated Critical with a CVSS score of 9.1, this flaw is remotely exploitable with low attack complexity, allowing authenticated users to achieve high confidentiality and integrity impacts through unauthorized data access and modification. There is currently no evidence of active exploitation, nor is public exploit code available in common repositories like Metasploit or ExploitDB. While not on the CISA KEV catalog, the vulnerability has garnered minimal community discussion, and its EPSS score suggests a very low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.12.2026CPE matchmatch criteria | cpe:2.3:a:mygardyn:cloud_api:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.