Unauthorized Access Vulnerability in Galette Membership Management Application
CVE-2025-58052

2.1LOW

Key Information:

Vendor

Galette

Status
Vendor
CVE Published:
19 December 2025

What is CVE-2025-58052?

The Galette Membership Management Application, widely used by non-profit organizations, has a vulnerability that allows attackers with a group manager role to bypass intended restrictions. This flaw, present in versions 0.9.6 up to 1.1.9, enables unauthorized access and modifications, undermining the role-based access control mechanisms designed to protect sensitive data. Exploitation is predominantly limited to malicious insiders or compromised accounts, emphasizing the importance of robust account management and monitoring. The vulnerability is addressed in version 1.2.0, which reinforces security protocols to prevent such breaches.

Affected Version(s)

galette >= 0.9.6, < 1.2.0

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-58052 : Unauthorized Access Vulnerability in Galette Membership Management Application