CVE Vulnerabilities

CVE-2025-35114

Use of Default Credentials

Published: Aug 26, 2025 | Modified: Sep 02, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Agiloft Release 28 contains several accounts with default credentials that could allow local privilege escalation. The password hash is known for at least one of the accounts and the credentials could be cracked offline. Users should upgrade to Agiloft Release 30.

Weakness

The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.

Affected Software

Name Vendor Start Version End Version
Agiloft Atlassian 19 (including) 30 (excluding)

Potential Mitigations

References