Access Control Vulnerability in Heureka Plugin by Heureka Group
CVE-2025-57907
5.3MEDIUM
What is CVE-2025-57907?
Heureka Group's Heureka plugin exhibits a missing authorization flaw that allows users to access functionalities that are not properly constrained by access control lists (ACLs). This vulnerability affects versions of the Heureka plugin from its inception up to 1.1.0, potentially compromising user security and data integrity.
Affected Version(s)
Heureka <= 1.1.0