Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 28 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Nov 2025 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a higher role such as admin) via the user-edit endpoint by supplying or modifying role_id or organisation_id fields in the edit request. | |
| First Time appeared |
Cerebrate-project
Cerebrate-project cerebrate |
|
| Weaknesses | CWE-472 | |
| CPEs | cpe:2.3:a:cerebrate-project:cerebrate:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cerebrate-project
Cerebrate-project cerebrate |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-28T15:18:23.211Z
Reserved: 2025-11-28T00:00:00.000Z
Link: CVE-2025-66385
Updated: 2025-11-28T15:18:20.551Z
Status : Deferred
Published: 2025-11-28T07:15:59.700
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-66385
No data.
OpenCVE Enrichment
No data.