Junglewise Threat Intelligence

CVE-2025-12059: Logo Software j-Platform sensitive information disclosure via access control bypass

CVE-2025-12059 · Severity: critical · CVSS 9.8 · Published 2026-02-11

Vendors: Logo Software.

Executive brief

Logo j-Platform, an enterprise resource planning (ERP) solution, contains a vulnerability that exposes sensitive information to unauthorized users. This flaw allows external attackers to access internal files or directories that should be restricted, potentially leading to the theft of corporate data or full system compromise. Organizations using affected versions should update to version 3.34.8.9 or later to secure their operations.

Technical details

A vulnerability classified as CWE-538 (Insertion of Sensitive Information into Externally-Accessible File or Directory) exists in Logo Software j-Platform. The root cause is incorrectly configured access control security levels, which fail to restrict access to sensitive files or directories from the network. An unauthenticated remote attacker can exploit this flaw with low complexity and no user interaction to gain unauthorized access to sensitive data, potentially impacting confidentiality, integrity, and availability. The issue is addressed in version 3.34.8.9.

Affected products

  • Logo Software Industry and Trade Inc. j-Platform From 3.29.6.4 before 3.34.8.9

Timeline

  • 2026-02-11: advisory: Initial advisory published by TR-CERT/USOM
  • 2026-02-11: disclosed

References