Junglewise Threat Intelligence

CVE-2025-11242: Teknolist Okulistik SSRF vulnerability

CVE-2025-11242 · Severity: critical · CVSS 9.8 · Published 2026-02-10

Executive brief

Okulistik, an educational platform, contains a critical security flaw that allows unauthorized individuals to force the server to make requests to internal or external systems. This could lead to the exposure of sensitive internal data, unauthorized access to private services, or the disruption of platform operations. The vulnerability is particularly severe because it can be exploited remotely without needing any user credentials.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in the Teknolist Okulistik platform. The flaw allows a remote, unauthenticated attacker to send crafted requests to the application, which the server then executes. This can be used to scan internal networks, access metadata services, or bypass firewalls to reach internal systems that are not intended to be public-facing. The vulnerability is rated critical with a CVSS score of 9.8, indicating high impact on confidentiality, integrity, and availability. Affected versions include those up to 21102025.

Affected products

  • Teknolist Computer Systems Software Publishing Industry and Trade Inc. Okulistik through 21102025

Timeline

  • 2026-02-10: advisory: Initial publication of the CVE record
  • 2026-06-04: other: CVE record modified with additional references

References