CVE 9.1 CRITICAL

CVE-2025-68721_CVE-2025-68721

9.1 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegated admin account with zero permissions can bypass access control checks and gain unauthorized access to the SSL Certificates management endpoint (page=sslcerts). This allows the attacker to view, download, upload, and delete SSL certificate files, despite lacking the necessary privileges to access the Security & Filtering section.

AI Analysis

Improper access control vulnerability in the WebAdmin interface allowing unauthorized access to SSL Certificates management endpoint

Basic Information

ID CVE-2025-68721
Source mitre
Published Feb 5, 2026 at 00:00
Modified Feb 5, 2026 at 20:27

Affected Product

Vendor Axigen
Product Axigen Mail Server
Version before 10.5.57
Affected Versions n/a n/a n/a

CWE Classification

AI Assessment

AI Score 9.1 / 10
AI Severity Critical
Vendor Axigen
Product Axigen Mail Server
Version before 10.5.57

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.