Junglewise Threat Intelligence

CVE-2025-6967: Sarman Soft CMS authentication bypass via Execution After Redirect

CVE-2025-6967 · Severity: high · CVSS 8.7 · Published 2026-02-10

Technologies: Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. CMS.

Executive brief

A security flaw exists in the Sarman Soft Content Management System (CMS), which is used to manage and publish website content. This vulnerability allows unauthorized individuals to bypass security checks and potentially gain access to sensitive data or administrative functions. Because the vendor has not responded to reports of this issue, the software remains vulnerable, posing a risk of data theft or unauthorized site modification.

Technical details

The Sarman Soft CMS contains an Execution After Redirect (EAR) vulnerability (CWE-698). This occurs when the application fails to stop code execution after sending a redirect header to the user's browser, allowing the rest of the page's logic to run. An unauthenticated remote attacker can exploit this to bypass authentication mechanisms or perform JSON hijacking (JavaScript Hijacking) to steal sensitive data. The vulnerability affects all versions through 10022026, and as of the disclosure date, no patch has been released by the vendor.

Affected products

  • Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. CMS through 10022026

Timeline

  • 2026-02-10: disclosed
  • 2026-02-10: advisory: Initial advisory published by USOM/TR-CERT

References