CVE-2025-65742

8.2

Newgen · OmniDocs

Newgen OmniDocs v11.0 contains an unauthenticated Broken Function Level Authorization vulnerability allowing sensitive information disclosure and full account takeover via crafted API requests.

Executive summary

An unauthenticated Broken Function Level Authorization vulnerability in Newgen OmniDocs v11.0 poses a critical risk of full account takeover and sensitive data exposure.

Vulnerability

This vulnerability involves a Broken Function Level Authorization (BFLA) flaw that allows unauthenticated remote attackers to bypass access controls, enabling them to manipulate API endpoints to achieve full account takeover.

Business impact

The potential for full account takeover and unauthorized access to sensitive information constitutes a severe business risk, including potential regulatory non-compliance, loss of intellectual property, and significant reputational damage. With a CVSS score of 8.2, this vulnerability is classified as High severity, reflecting the ease of exploitation and the significant impact on confidentiality and integrity.

Remediation

Immediate Action: Contact Newgen support immediately to obtain security patches for OmniDocs v11.0, as no public fix is currently confirmed.

Proactive Monitoring: Review API access logs for anomalous, high-frequency requests or unauthorized access patterns targeting administrative or user-management endpoints.

Compensating Controls: Implement strict network-level access controls to limit exposure of the OmniDocs API to untrusted networks and deploy a Web Application Firewall to block suspicious, non-authenticated API requests.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists on GitHub, as referenced in the vulnerability documentation.

Analyst recommendation

Given the availability of a public proof-of-concept and the high potential impact, organizations using Newgen OmniDocs v11.0 must prioritize this issue. Administrators should immediately restrict network access to the affected infrastructure while working with the vendor to secure and apply the necessary patches to prevent unauthorized account takeovers.

Sources