Executive brief
Beakon is a safety, risk, and compliance management platform used by organizations to handle contractor management, audits, and incident reporting. A security flaw in versions prior to 5.4.3 allows users with low-level access to bypass security controls and gain full administrative rights. This could allow an unauthorized user to take control of the system, access sensitive safety data, or execute unauthorized commands, potentially disrupting business operations and compliance tracking.
Technical details
An improper access control vulnerability (CWE-284) exists in the Beakon Application in versions prior to 5.4.3. The flaw allows an authenticated user with low-level permissions to bypass authorization checks and escalate their privileges to an administrative level. Once escalated, the attacker can execute commands with full Administrator rights. The vulnerability is reachable over the network, and while the description mentions authenticated attackers, the provided CVSS vector (AV:N/AC:L/PR:N/UI:N) suggests a lack of required privileges for the initial vector. Users should upgrade to version 5.4.3 or later to remediate this issue.
Affected products
- Beakon Beakon Application before 5.4.3
Timeline
- 2025-09-02: advisory
- 2025-09-11: other: Initial analysis by NIST completed