Junglewise Threat Intelligence

CVE-2025-13506: Nebim V3 ERP privilege escalation from database to OS

CVE-2025-13506 · Severity: high · CVSS 8.8 · Published 2025-12-12

Executive brief

Nebim V3 ERP, a comprehensive enterprise resource planning software, contains a security flaw that allows users with low-level access to gain excessive control over the underlying server. An attacker could exploit this to move from the database environment to the operating system, potentially leading to full system takeover, data theft, or service disruption. This poses a significant risk to business operations and the confidentiality of corporate data.

Technical details

A vulnerability classified as CWE-250 (Execution with Unnecessary Privileges) exists in Nebim V3 ERP versions 2.0.59 through 3.0.1. The flaw allows an authenticated user with low privileges to escalate their control from the database layer to the host operating system. This is likely due to the application or database service running with excessive permissions or providing a mechanism to execute system-level commands. An attacker can achieve full confidentiality, integrity, and availability impact on the affected server. Users are advised to upgrade to version 3.0.1 or later to remediate the issue.

Affected products

  • Nebim Neyir Computer Industry and Services Inc. Nebim V3 ERP 2.0.59 to 3.0.1 (exclusive)

Timeline

  • 2025-12-12: disclosed: Initial publication of the CVE record
  • 2026-06-04: advisory: Last modified date on NVD record

References