Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-30194 | SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys under certain conditions, allowing unauthorized privilege escalation to admin via SSH. |
| Link | Providers |
|---|---|
| https://advisories.softiron.cloud/ |
|
Fri, 20 Feb 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys under certain conditions, allowing unauthorized privilege escalation to admin via SSH. | SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys under certain conditions, allowing unauthorized privilege escalation to admin via SSH. Affects non-production debug and internal development builds created between versions 2.5.0 and 2.6.3. No generally available (GA) or customer-released production builds were affected. There is no evidence that this issue was exposed in customer environments or production deployments. |
| Title | Non-admin users may erroneously be granted cluster-level SSH access | Improper SSH Key Handling in Internal Debug Builds May Grant Cluster-Level Access to Non-Administrative Users |
| Metrics |
cvssV4_0
|
cvssV4_0
|
Fri, 19 Sep 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Softiron
Softiron hypercloud |
|
| Vendors & Products |
Softiron
Softiron hypercloud |
Thu, 18 Sep 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Sep 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys under certain conditions, allowing unauthorized privilege escalation to admin via SSH. | |
| Title | Non-admin users may erroneously be granted cluster-level SSH access | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: SoftIron
Published:
Updated: 2026-02-20T15:59:52.914Z
Reserved: 2025-09-17T18:55:07.506Z
Link: CVE-2025-10650
Updated: 2025-09-18T20:43:18.388Z
Status : Deferred
Published: 2025-09-18T19:15:37.143
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-10650
No data.
OpenCVE Enrichment
Updated: 2025-09-19T09:35:18Z
EUVD