Vulnerability in the access control system of the GAMS licensing system that allows unlimited valid licenses to be generated, bypassing any usage restrictions. The validator uses an insecure checksum algorithm; knowing this algorithm and the format of the license lines, an attacker can recalculate the checksum and generate a valid license to grant themselves full privileges without credentials or access to the source code, allowing them unrestricted access to GAMS's mathematical models and commercial solvers.
References
| Link | Resource |
|---|---|
| https://www.gams.com/latest/docs/RN_51.html | Release Notes |
| https://www.incibe.es/en/incibe-cert/notices/aviso/authorization-bypass-gams-gams-development-corp | Third Party Advisory |
Configurations
History
03 Feb 2026, 17:19
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Gams gams
|
|
| CPE | cpe:2.3:a:gams:gams:*:*:*:*:*:*:*:* |
Information
Published : 2025-12-02 14:16
Updated : 2026-02-03 17:19
NVD link : CVE-2025-41086
Mitre link : CVE-2025-41086
CVE.ORG link : CVE-2025-41086
JSON object : View
Products Affected
gams
- gams
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
