Temenos develops banking and financial-services software platforms such as T24 and CWX that process high-value transactions and customer data, creating a sensitive attack surface where access-control lapses carry substantial downstream risk. The observed vulnerability pattern centers on path-traversal flaws and incorrect permission assignments for critical resources, reflecting the file-system and privilege-boundary complexity typical of enterprise financial middleware. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Temenos over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14251HIGH An issue was discovered in T24 in TEMENOS Channels R15.01. The login page presents JavaScript functions to access a document on the server once successfully authenticated. However, | Dec 9, 2019 | 7.5 | 37 | NO | YES |
CVE-2022-45287HIGH An access control issue in Registration.aspx of Temenos CWX 8.5.6 allows authenticated attackers to escalate privileges and perform arbitrary Administrative commands. | Jun 21, 2023 | 8.8 | 26 | NO | NO |
CVE-2019-13403HIGH Temenos CWX version 8.9 has an Broken Access Control vulnerability in the module /CWX/Employee/EmployeeEdit2.aspx, leading to the viewing of user information. | Jul 17, 2019 | 7.5 | 24 | NO | NO |
CVE-2023-34797MEDIUM Broken access control in the Registration page (/Registration.aspx) of Termenos CWX v8.5.6 allows attackers to access sensitive information. | Jun 15, 2023 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Temenos.
Media articles that mention a CVE ID that affects a product developed by Temenos — matched by CVE ID, not by vendor name.