Race Condition Vulnerability in Wind River Products
CVE-2025-26499

6MEDIUM

What is CVE-2025-26499?

A race condition vulnerability exists in Wind River products allowing a scenario where one user may be granted session tokens intended for another user under high system load. This can result in inadvertent impersonation, where a user accesses another's system rights and data. Although this situation cannot be intentionally exploited, it poses a risk during concurrent actions by multiple users, leaving sensitive information potentially exposed. Mitigation strategies are essential to address this security issue.

Affected Version(s)

Wind River Studio Developer Wind River Studio Developer 24.11 < 24.11>=

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.