Insecure Access Control in Asseco SEE Live 2.0
CVE-2025-66956

9.9CRITICAL

Key Information:

Vendor

Asseco SEE

Vendor
CVE Published:
11 March 2026

What is CVE-2025-66956?

A vulnerability identified in Asseco SEE Live 2.0 allows unauthorized remote access to attachments through computable URLs. This flaw can result in the execution of privileged actions, compromising the confidentiality and integrity of sensitive data. Attackers may exploit this vulnerability to gain access to user data and execute malicious files, highlighting the critical need for enhanced access control measures.

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.