Access Control Misconfiguration in Logpoint Exposes Sensitive Information
CVE-2025-66360

6.9MEDIUM

Key Information:

Vendor

Logpoint

Status
Vendor
CVE Published:
27 November 2025

What is CVE-2025-66360?

An access control misconfiguration was identified in Logpoint prior to version 7.7.0, which exposes sensitive internal service information related to Redis to users with limited administrative privileges. This vulnerability can potentially allow these users to escalate their privileges and gain unauthorized access to data that should be restricted.

Affected Version(s)

SIEM 0 < 7.7.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.