Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnerability has been fixed in GAMS version 51.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 03 Feb 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gams gams
|
|
| CPEs | cpe:2.3:a:gams:gams:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gams access Control System
|
Gams gams
|
Fri, 30 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gams
Gams access Control System |
|
| CPEs | cpe:2.3:a:gams:access_control_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gams
Gams access Control System |
|
| Metrics |
cvssV3_1
|
Tue, 02 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Dec 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the access control system of the GAMS licensing system that allows unlimited valid licenses to be generated, bypassing any usage restrictions. The validator uses an insecure checksum algorithm; knowing this algorithm and the format of the license lines, an attacker can recalculate the checksum and generate a valid license to grant themselves full privileges without credentials or access to the source code, allowing them unrestricted access to GAMS's mathematical models and commercial solvers. | |
| Title | Authorization bypass in GAMS from GAMS Development Corp. | |
| First Time appeared |
Ams Development Corp.
Ams Development Corp. gams |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:ams_development_corp.:gams:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ams Development Corp.
Ams Development Corp. gams |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-12-02T14:24:21.854Z
Reserved: 2025-04-16T09:09:36.724Z
Link: CVE-2025-41086
Updated: 2025-12-02T14:24:17.304Z
Status : Analyzed
Published: 2025-12-02T14:16:25.070
Modified: 2026-02-03T17:19:06.673
Link: CVE-2025-41086
No data.
OpenCVE Enrichment
No data.