CVE-2025-6083

In ExtremeCloud Universal ZTNA, a syntax error in the 'searchKeyword' condition caused queries to bypass the owner_id filter. This issue may allow users to search data across the entire table instead of being restricted to their specific owner_id.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:extremenetworks:extremecloud_universal_ztna:*:*:*:*:*:*:*:*
cpe:2.3:a:extremenetworks:extremecloud_universal_ztna:25.2.0:-:*:*:*:*:*:*

History

No history.

Information

Published : 2025-06-13 21:15

Updated : 2026-01-08 21:39


NVD link : CVE-2025-6083

Mitre link : CVE-2025-6083

CVE.ORG link : CVE-2025-6083


JSON object : View

Products Affected

extremenetworks

  • extremecloud_universal_ztna
CWE
CWE-287

Improper Authentication

NVD-CWE-noinfo