Authorization Flaw in Q-Free MaxTime Allows Unauthorized User Group Deletion
CVE-2025-26368
8.1HIGH
What is CVE-2025-26368?
A critical authorization vulnerability exists in Q-Free MaxTime, specifically in the user-groups route. This flaw allows an authenticated attacker with low privileges to perform unauthorized actions, including the deletion of user groups, by sending specially crafted HTTP requests. This vulnerability emphasizes the importance of implementing proper access controls within applications to prevent misuse.
Affected Version(s)
MaxTime 0 <= 2.11.0
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Diego Giubertoni of Nozomi Networks found this bug during a security research activity.
