Junglewise Threat Intelligence

CVE-2025-56467: Axis Bank Axis Mobile App authentication bypass in UPI Service

CVE-2025-56467 · Severity: medium · CVSS 6.5 · Published 2025-09-12

Executive brief

A security flaw in the Axis Bank mobile application allows unauthorized access to sensitive financial information. By navigating through specific menus, a user can view account balances, transaction histories, and UPI management settings without providing the required security PIN. This could lead to the exposure of private financial data if an unauthorized person gains access to a customer's unlocked mobile device.

Technical details

An authentication bypass vulnerability exists in the Axis Mobile App version 9.9. The flaw is located within the UI navigation logic; specifically, by navigating to the 'Pay to contacts' section and then using the back button, the application exposes the UPI Service interface. This interface allows access to 'Check Balance', 'My Transactions', and 'Manage UPI' functions without requiring the mandatory MPIN or UPI PIN authentication. While the vendor disputes the severity, claiming it is an intended feature, it effectively bypasses intended access controls for sensitive financial data. An attacker with local access to the device or a user session could exploit this to exfiltrate PII and financial history.

Affected products

  • Axis Bank Limited Axis Mobile App 9.9

Timeline

  • 2025-09-12: advisory: NVD publication date
  • 2025-09-15: other: Vulnerability marked as disputed by the vendor

References