Junglewise Threat Intelligence

CVE-2025-0640: Akinsoft OctoCloud authorization bypass in user-controlled keys

CVE-2025-0640 · Severity: medium · CVSS 4.7 · Published 2025-09-02

Technologies: AKINSOFT OctoCloud. Vendors: AKINSOFT.

Executive brief

Akinsoft OctoCloud, a business management and accounting software suite, contains a security flaw that allows users to bypass authorization checks. By manipulating specific keys or identifiers, an authorized user with high-level privileges could access resources or data they are not intended to see. This could lead to the exposure of sensitive business information or internal resource leaks.

Technical details

An Authorization Bypass Through User-Controlled Key (CWE-639) vulnerability exists in Akinsoft OctoCloud versions s1.09.02 through v1.11.01. The flaw allows a remote attacker with high privileges (PR:H) to bypass authorization mechanisms by providing or manipulating a key that identifies a specific resource. This can result in unauthorized access to data or 'Resource Leak Exposure.' The attack is reachable over the network and requires no user interaction. Users are advised to update to version v1.11.01 or later to remediate the issue.

Affected products

  • Akinsoft OctoCloud From s1.09.02 before v1.11.01

Timeline

  • 2025-09-02: advisory: Initial publication of the vulnerability advisory.
  • 2025-09-02: disclosed: Vulnerability disclosed by TR-CERT (USOM).

References

Related threats