Junglewise Threat Intelligence

CVE-2025-8463: SecHard Information Technologies SecHard authorization bypass via forceful browsing

CVE-2025-8463 · Severity: medium · CVSS 5.3 · Published 2025-09-17

Executive brief

A security flaw in SecHard, a platform used for security hardening and compliance management, allows authenticated users to access data they are not authorized to see. By manipulating specific identifiers in web requests, a user with low-level access can bypass security checks to view sensitive information. This could lead to the exposure of internal configuration details or other protected data within the system.

Technical details

An Authorization Bypass Through User-Controlled Key (CWE-639) exists in SecHard versions prior to 3.6.2-20250805. The vulnerability allows an authenticated attacker with low privileges to perform 'forceful browsing' by manipulating keys or parameters within the application's requests. By supplying different identifiers that the application fails to properly validate against the user's session permissions, the attacker can access sensitive information or objects belonging to other users or the system. The attack requires network connectivity and valid low-level credentials, but no user interaction.

Affected products

  • SecHard Information Technologies SecHard before 3.6.2-20250805

Timeline

  • 2025-09-17: disclosed
  • 2025-09-17: advisory

References