Unverified Ownership in Mautic - CVE-2025-9822

 

Unverified Ownership in Mautic - CVE-2025-9822

Published: May 25, 2026


Vulnerability identifier: #VU132235
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-9822
CWE-ID: CWE-283
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to unverified ownership in the elfinder configuration handling when changing application configuration. A remote privileged user can modify the configuration to disclose sensitive information.

An administrator can extract secrets such as database credentials that are not normally available.


Affected software

Mautic

How to mitigate CVE-2025-9822

Install security update from vendor's website.

Mautic - addressed in versions 4.4.18, 5.2.8, 6.0.5

External References

Related Security Bulletins