Missing Authentication for Critical Function in Eclipse Che - CVE-2025-12548

 

Missing Authentication for Critical Function in Eclipse Che - CVE-2025-12548

Published: December 3, 2025 / Updated: March 25, 2026


Vulnerability identifier: #VU119113
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-12548
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to CHE machine-exec API is exposed by default on port 3333/TCP and does not require authentication. A remote non-authenticated attacker can obtain SSH private keys that are configured by other devspaces user and compromise the affected system.


Affected software

Eclipse Che
Red Hat OpenShift Dev Spaces

How to mitigate CVE-2025-12548

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Red Hat OpenShift Dev Spaces - addressed in versions 3.22.1, 3.23.1, 3.24.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins