CVE Vulnerabilities

CVE-2025-13292

Improper Privilege Management

Published: Dec 06, 2025 | Modified: Dec 06, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in Apigee-X allowed an attacker to gain unauthorized read and write access to Apigee Analytics (AX) data and access logs belonging to other Apigee customer organizations.

Apigee-X was found to be vulnerable.

This vulnerability was patched in version 1-16-0-apigee-3. No user action is required for this.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Potential Mitigations

References