Executive brief
FlexNet Manager Suite is a software asset management solution used by organizations to track and optimize their software licenses. A security flaw in the 2025 R1 and R2 versions could allow an authorized user to access attachment files they are not permitted to see. This could lead to the exposure of sensitive business documentation or licensing data stored within the system.
Technical details
An improper access control vulnerability (CWE-284) exists in Flexera FlexNet Manager Suite 2025 R1 and R2. The flaw allows a network-based attacker with low privileges (PR:L) to bypass intended access restrictions and view attachment files without proper authorization. The vulnerability stems from insufficient validation of user permissions when requesting file attachments. According to the vendor, version 2026 R1 is unaffected, implying a fix is available in that release or subsequent updates.
Affected products
- Flexera FlexNet Manager Suite 2025 R1, 2025 R2
Timeline
- 2026-06-19: disclosed
- 2026-06-19: advisory