Junglewise Threat Intelligence

CVE-2026-12693: Vimesoft Enterprise Video Platform authorization bypass via user-controlled key

CVE-2026-12693 · Severity: critical · CVSS 9.4 · Published 2026-07-17

Technologies: Vimesoft Inc. Enterprise Video Platform.

Executive brief

Vimesoft Enterprise Video Platform, a system used by organizations to manage and stream corporate video content, contains a critical security flaw. This vulnerability allows unauthorized individuals to bypass security checks and access restricted functions or data by manipulating user-controlled keys. An attacker could potentially view private videos, modify system settings, or disrupt video services without needing a valid login.

Technical details

An authorization bypass vulnerability (CWE-639) exists in Vimesoft Enterprise Video Platform versions 3.11.0.0 through 3.24.x. The flaw is rooted in the use of user-controlled keys that are not properly validated against Access Control Lists (ACLs). A remote, unauthenticated attacker can exploit this by providing malicious keys or identifiers to access functionality or data that should be restricted. This can lead to full compromise of data confidentiality and integrity. The issue is addressed in version 3.25.0.

Affected products

  • Vimesoft Inc. Enterprise Video Platform 3.11.0.0 to 3.25.0

Timeline

  • 2026-07-17: disclosed
  • 2026-07-17: advisory

References