Junglewise Threat Intelligence

CVE-2025-66698: Semantic Machines Veda authentication bypass in API endpoints

CVE-2025-66698 · Severity: high · CVSS 8.6 · Published 2026-01-13

Executive brief

Semantic Machines Veda, a platform used for managing complex organizational data and knowledge systems, contains a security flaw that allows unauthorized individuals to bypass login requirements. By sending a specially formatted web request, an attacker can gain access to sensitive internal information, including employee records, personal identifiable information (PII), and system configurations. This could lead to significant data exposure and a breach of privacy for the affected organization.

Technical details

An authentication bypass vulnerability exists in Semantic Machines Veda v5.4.8 due to improper validation of the 'ticket' parameter in various API endpoints. The system fails to check for empty values, treating an empty string as a valid session identifier. Additionally, the application reportedly contains a hardcoded 'systicket' that can be used to achieve the same result. A remote, unauthenticated attacker can exploit this by sending crafted HTTP requests (e.g., to /get_individual or /is_ticket_valid) to enumerate users, policies, and sensitive PII such as birth dates and contact information. As of the disclosure date, the vendor has not responded to reports, and no official patch is available.

Affected products

  • Semantic Machines Veda 5.4.8

Timeline

  • 2025-11-18: other: Vulnerability discovered by researcher
  • 2026-01-09: other: CVE ID assigned
  • 2026-01-13: disclosed: Public disclosure due to lack of vendor response
  • 2026-01-13: advisory

References