CVE-2025-26499
MEDIUMDescription
Under heavy system utilization a random race condition can occur during authentication or token refresh operation. This flaw allows one user to be granted a token intended for another user, resulting in impersonation until the session is ended. This flaw cannot be intentionally exploited due to the required concurring action by two users. However, if the event occurs a user would be inadvertently exposed to another user’s system rights and data access.
Is your site exposed to CVE-2025-26499?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2025-26499? +
How severe is CVE-2025-26499? +
How do I check if I'm vulnerable to CVE-2025-26499? +
Related Vulnerabilities
When the Global Pointer (GP) relative addressing is enabled (CONFIG_RISCV_GP=y), the gp reg points at 0x800 bytes past the start …
XWiki is a generic wiki platform. Any user with edit right on a page (could be the user's profile) can …
A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all …
System call entry on Cortex M (and possibly R and A, but I think not) has a race which allows …
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data …
Privilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.