Executive brief
Vimesoft Enterprise Video Platform, a system used by organizations to manage and stream video content, contains a security flaw that fails to check user permissions for certain functions. This allows unauthorized individuals to access restricted administrative or operational features without logging in. An attacker could exploit this to disrupt video services or modify system settings, potentially leading to a total loss of service or unauthorized changes to corporate media assets.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Vimesoft Enterprise Video Platform versions 3.11.0.0 through 3.25.0. The application fails to properly enforce Access Control Lists (ACLs) on specific functional endpoints, allowing unauthenticated remote attackers to execute actions that should be restricted to authorized users. According to the CVSS vector, the attack is network-based, requires no privileges, and involves no user interaction. Successful exploitation can lead to high impacts on system integrity and availability, though confidentiality is reportedly not affected. Users are advised to upgrade to version 3.25.0 or later to remediate the issue.
Affected products
- Vimesoft Inc. Enterprise Video Platform 3.11.0.0 to 3.25.0
Timeline
- 2026-07-17: disclosed
- 2026-07-17: advisory