Unauthenticated File Read and SMB Coercion Vulnerability in UnForm Server
CVE-2025-34350

8.7HIGH

Key Information:

Vendor
CVE Published:
25 November 2025

What is CVE-2025-34350?

UnForm Server prior to version 10.1.15 exposes a vulnerability within its Doc Flow feature, specifically the 'arc' endpoint, allowing for unauthenticated arbitrary file reads. This occurs because the application permits unvalidated input in the user-supplied 'pp' parameter, enabling attackers to specify local filesystem paths. Additionally, on Windows systems, attackers can exploit this vulnerability by providing UNC paths, which may trigger the server to perform outbound SMB authentication and expose NTLM credentials. Such a security lapse can lead to unauthorized access to sensitive files and provide pathways for further network exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

UnForm Server 0 < 10.1.15

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Victor Morales of GM Sectec, Corp.
Jan Rodriguez of GM Sectec, Corp.
.