Junglewise Threat Intelligence

CVE-2025-60357: AhnLab EPP Management NoSQL injection in agentEvent list endpoint

CVE-2025-60357 · Severity: info · CVSS 0 · Published 2026-07-17

Executive brief

AhnLab EPP Management, a platform used by organizations to manage endpoint security and malware protection, contains a vulnerability in its event logging component. An authenticated user can manipulate database queries to bypass intended restrictions and access sensitive information, including personally identifiable information (PII) like usernames, IP addresses, and department details. This could lead to unauthorized data disclosure and assist in further targeted attacks against the organization's infrastructure.

Technical details

A NoSQL injection vulnerability exists in AhnLab EPP Management v1.0.14.32-6249 and earlier via the '/api/console/ems/eventlog/agentEvent/list' endpoint. The application fails to properly sanitize user-supplied input within the MongoDB query parameters of the request body. An authenticated attacker can inject MongoDB operators (such as $lookup and $match) to manipulate the aggregation pipeline. This allows for the extraction of sensitive information from the 'tb_agent_event_log' collection, including PII such as computer names, login IDs, MAC addresses, and network configurations. The vendor has released a patch (moving from version P14.32 to P16.25) to address this issue.

Affected products

  • AhnLab EPP Management 1.0.14.32-6249 and earlier

Timeline

  • 2024-05-24: disclosed: Vulnerability discovered and reported by researcher
  • 2024-08: patched: AhnLab released patch version P16.25
  • 2026-07-17: advisory: CVE-2025-60357 published

References

Related threats