Junglewise Threat Intelligence

CVE-2025-13480: Fudo Security Fudo Enterprise incorrect authorization in API endpoints

CVE-2025-13480 · Severity: medium · CVSS 6.5 · Published 2026-04-20

Executive brief

Fudo Enterprise, a Privileged Access Management (PAM) solution used to monitor and secure administrative sessions, contains a vulnerability that allows users with low-level access to view restricted information. An attacker could exploit this to access sensitive system logs and configuration details that should only be visible to administrators. This could lead to the exposure of internal system architecture or operational data, potentially aiding further attacks.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in Fudo Enterprise versions 5.5.0 through 5.6.2. The flaw is located within specific API endpoints that fail to properly enforce administrative privilege requirements. A remote attacker with low-privileged credentials can bypass these checks to retrieve sensitive system logs and portions of the system configuration. While the vendor's CVSS 4.0 assessment suggests an adjacent network vector (AV:A), NVD's 3.1 assessment classifies it as reachable via the network (AV:N). The issue is resolved in Fudo Enterprise version 5.6.3.

Affected products

  • Fudo Security Fudo Enterprise 5.5.0 through 5.6.2

Timeline

  • 2026-04-20: disclosed
  • 2026-04-20: advisory: Initial advisory by CERT Polska
  • 2026-04-20: patched: Fixed in version 5.6.3

References