CVE 7.5 HIGH

Agiloft local privilege escalation via default credentials_CVE-2025-35114

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

Agiloft Release 28 contains several accounts with default credentials that could allow local privilege escalation. The password hash is known for at least one of the accounts and the credentials could be cracked offline. Users should upgrade to Agiloft Release 30.

Basic Information

ID CVE-2025-35114
Source cisa-cg
Published Aug 26, 2025 at 22:18

Affected Product

Vendor Agiloft
Product Agiloft
Affected Versions Agiloft Agiloft 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.