CVE-2025-69907 is an unauthenticated information disclosure vulnerability in Newgen OmniDocs, specifically affecting the /omnidocs/GetListofCabinet API endpoint. This allows remote attackers to retrieve sensitive internal configuration details, such as cabinet names and database metadata, without requiring any credentials. Rated HIGH with a CVSS score of 7.5, the vulnerability has a network attack vector and low attack complexity, potentially leading to unauthorized enumeration of backend deployment details. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion, indicating potential interest from threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.