Executive brief
A privilege escalation vulnerability has been identified in FlexNet Manager Suite 2025 R1. This software is used by organizations to manage software licenses and optimize IT assets. An attacker who already has low-level, read-only access to account settings can exploit this flaw to gain full Administrator privileges, potentially allowing them to modify configurations, access sensitive licensing data, or disrupt operations.
Technical details
An improper access control vulnerability (CWE-284) exists in FlexNet Manager Suite 2025 R1. The flaw resides in the account settings component, where the system fails to properly enforce permission boundaries for users with read-only access. A remote, authenticated attacker with low-level privileges can exploit this to escalate their permissions to the Administrator level. This allows for full control over the suite's management functions. The vulnerability is tracked as CVE-2026-4026 and has been assigned a CVSS 4.0 score of 8.7 by the vendor.
Affected products
- Flexera FlexNet Manager Suite 2025 R1
Timeline
- 2026-06-19: disclosed: CVE-2026-4026 published by Flexera