Executive brief
Vimesoft Enterprise Video Platform, a system used by organizations to manage and stream corporate video content, contains a critical security flaw. This vulnerability allows unauthorized individuals to bypass security checks and access restricted functions or data by manipulating user-controlled keys. An attacker could potentially view private videos, modify system settings, or disrupt video services without needing a valid login.
Technical details
An authorization bypass vulnerability (CWE-639) exists in Vimesoft Enterprise Video Platform versions 3.11.0.0 through 3.24.x. The flaw is rooted in the use of user-controlled keys that are not properly validated against Access Control Lists (ACLs). A remote, unauthenticated attacker can exploit this by providing malicious keys or identifiers to access functionality or data that should be restricted. This can lead to full compromise of data confidentiality and integrity. The issue is addressed in version 3.25.0.
Affected products
- Vimesoft Inc. Enterprise Video Platform 3.11.0.0 to 3.25.0
Timeline
- 2026-07-17: disclosed
- 2026-07-17: advisory