Improper access control in MeterSphere - CVE-2025-62604
Published: April 24, 2026
MeterSphere
Detailed vulnerability description
The vulnerability allows a remote user to log in as any user and retrieve arbitrary user information.
The vulnerability exists due to improper access control in the authentication mechanism when handling login requests. A remote user can send a crafted login request to log in as any user and retrieve arbitrary user information.
The issue can be exploited remotely without user interaction.