WebSocket Authentication Vulnerability in Outline Service
CVE-2025-68663

6.9MEDIUM

Key Information:

Vendor

Outline

Status
Vendor
CVE Published:
11 February 2026

What is CVE-2025-68663?

A vulnerability in Outline's WebSocket authentication mechanism allowed suspended users to retain or initiate real-time WebSocket connections. This oversight enabled them to receive sensitive operational updates despite account suspension. The issue has been rectified in Outline's version 1.1.0, significantly enhancing the integrity of user account management and operational security.

Affected Version(s)

outline < 1.1.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.