Vantage6 is a federated learning and privacy-preserving data-collaboration platform that enables organizations to conduct distributed analytics without centralizing sensitive data, placing its vulnerability surface at the intersection of authentication, authorization, and data-access control. Vulnerabilities affecting the vendor skew toward serious outcomes and concentrate in its core platform and web-interface components around authorization bypass, improper access control, and exposure of sensitive information—weakness classes that directly threaten the integrity of its privacy guarantees. Defenders should prioritize patches for this vendor's releases given the elevated severity tendency and the sensitive data context inherent to federated analytics deployments; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vantage6 over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-23929HIGH vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Currently, the refresh token is valid indefinitely. The refresh token should get a v | Mar 4, 2023 | 8.8 | 26 | NO | NO |
CVE-2024-21649HIGH The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Prior to 4.2.0, authenticated us | Jan 30, 2024 | 8.8 | 25 | NO | NO |
CVE-2025-43863CRITICAL vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. If attacker gets access | Jun 12, 2025 | 9.8 | 24 | NO | NO |
CVE-2024-21653CRITICAL The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Nodes and servers get a ssh con | Jan 30, 2024 | 9.8 | 24 | NO | NO |
CVE-2023-47631HIGH vantage6 is a framework to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). In affected versions a node does not che | Nov 14, 2023 | 8.8 | 24 | NO | NO |
CVE-2025-43866HIGH vantage6 is an open-source infrastructure for privacy preserving analysis. The JWT secret key in the vantage6 server is auto-generated unless defined by the user. The auto-generate | Jun 12, 2025 | 7.5 | 21 | NO | NO |
CVE-2023-23930HIGH vantage6 is privacy preserving federated learning infrastructure. Versions prior to 4.0.0 use pickle, which has known security issue, as a default serialization module but that has | Oct 11, 2023 | 7.2 | 21 | NO | NO |
CVE-2022-39228MEDIUM vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. vantage6 does not inform the user of wrong username/password combination if the user | Mar 1, 2023 | 6.5 | 21 | NO | NO |
CVE-2023-22738MEDIUM vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Assigning existing users to a different organizations is currently possible. It may | Mar 1, 2023 | 6.5 | 20 | NO | NO |
CVE-2024-23823MEDIUM vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. The vantage6 server has | Mar 14, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vantage6.
Media articles that mention a CVE ID that affects a product developed by Vantage6 — matched by CVE ID, not by vendor name.