8.6
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Description
Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access Control vulnerability. The endpoint fails to implement any authorization checks, allowing unauthenticated attackers to perform POST requests to register new user accounts in the application's local database. This bypasses the intended security architecture, which relies on an external Identity Provider for initial user registration and assumes that internal user creation is an administrative-only function. This vector can also be chained with other vulnerabilities for privilege escalation and complete compromise of application. This specific request can be used to also enumerate already registered user accounts, aiding in social engineering or further targeted attacks.
AI Analysis
Broken Access Control vulnerability in Primakon Pi Portal 1.0.18 allowing unauthenticated attackers to register new user accounts
Basic Information
ID
CVE-2025-64066
Source
mitre
Published
Nov 25, 2025 at 00:00
Modified
Nov 25, 2025 at 20:41
Affected Product
Vendor
Primakon
Product
Primakon Pi Portal
Version
1.0.18
Affected Versions
n/a n/a n/a
CWE Classification
AI Assessment
AI Score
8.6 / 10
AI Severity
High
Vendor
Primakon
Product
Primakon Pi Portal
Version
1.0.18