Junglewise Threat Intelligence

CVE-2025-8884: VHS ACE Center authorization bypass via user-controlled key

CVE-2025-8884 · Severity: medium · CVSS 5.5 · Published 2025-10-20

Executive brief

A security vulnerability has been identified in VHS ACE Center, a management software platform. An attacker with existing low-level access to the system can manipulate specific identifiers to bypass security checks and access information they are not authorized to see. This could lead to the unauthorized disclosure of sensitive data or the abuse of administrative privileges within the software.

Technical details

An authorization bypass vulnerability (CWE-639) exists in VHS ACE Center versions 3.10.100.1768 through 3.10.161.2254. The flaw stems from the application's reliance on user-controlled keys or identifiers to perform authorization checks. A local attacker with low privileges can modify these identifiers to access resources or perform actions associated with other users or higher-privileged accounts. The vulnerability has a CVSS score of 5.5, primarily impacting data confidentiality. Users are advised to update to version 3.10.161.2255 or later to remediate the issue.

Affected products

  • VHS Electronic Software Ltd. Co. ACE Center 3.10.100.1768 to 3.10.161.2254

Timeline

  • 2025-10-20: advisory: Initial publication of the CVE record.
  • 2026-06-05: other: CVE record modified with updated description and references.

References