Executive brief
A security flaw exists in the REST API of Ibexa and Ciril GROUP eZ Platform, a content management system used for digital experience and website management. This vulnerability allows unauthorized individuals to access sensitive internal data by guessing or cycling through object identification numbers. An attacker could exploit this to harvest private information without needing a username or password, potentially leading to data breaches and loss of confidentiality.
Technical details
An improper access control vulnerability, specifically an Insecure Direct Object Reference (IDOR), exists in the REST API of Ibexa and Ciril GROUP eZ Platform (formerly eZ Publish) versions 2.0.0 through 2.5.32. The root cause is a failure to properly validate user permissions when accessing objects via the API. A remote, unauthenticated attacker can exploit this by programmatically enumerating object IDs in API requests to retrieve sensitive data that should be restricted. This vulnerability is tracked as CWE-284 and CWE-639. Users are advised to check for patches from Ibexa or Ciril GROUP for the 2.x platform branch.
Affected products
- Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.0.0 through 2.5.32
Timeline
- 2026-03-06: disclosed: Initial disclosure of CVE-2025-70363
- 2026-03-06: advisory: NVD publication date