Authorization Flaw in Q-Free MaxTime Allows Unauthorized User Group Deletion
CVE-2025-26368

8.1HIGH

Key Information:

Vendor

Q-free

Status
Vendor
CVE Published:
12 February 2025

What is CVE-2025-26368?

A critical authorization vulnerability exists in Q-Free MaxTime, specifically in the user-groups route. This flaw allows an authenticated attacker with low privileges to perform unauthorized actions, including the deletion of user groups, by sending specially crafted HTTP requests. This vulnerability emphasizes the importance of implementing proper access controls within applications to prevent misuse.

Affected Version(s)

MaxTime 0 <= 2.11.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Diego Giubertoni of Nozomi Networks found this bug during a security research activity.
.