CVE-2025-67274

7.5

Continuous Software · Aangine

Aangine v.2025.2 contains an information disclosure vulnerability in multiple service modules that allows unauthenticated remote attackers to access sensitive data.

Executive summary

A critical information disclosure vulnerability in Continuous Software Aangine version 2025.2 allows unauthenticated remote attackers to exfiltrate sensitive data from the system.

Vulnerability

The vulnerability exists within the excel-integration-service template download, integration-persistence-service job listing, and portfolio-item-service data retrieval modules, which lack proper access controls for unauthenticated remote users.

Business impact

Successful exploitation of this vulnerability allows unauthorized actors to access sensitive information, potentially leading to a breach of proprietary data or internal system configurations. Given the CVSS score of 7.5, this high-severity flaw poses a significant risk to data confidentiality, necessitating immediate attention to prevent unauthorized data exposure.

Remediation

Immediate Action: Contact Continuous Software immediately to obtain the relevant security patch for version 2025.2, as a public fix is currently unknown.

Proactive Monitoring: Review web server and application access logs for unusual patterns of traffic targeting the excel-integration-service, integration-persistence-service, or portfolio-item-service endpoints.

Compensating Controls: Deploy a Web Application Firewall (WAF) rule to restrict access to the identified vulnerable endpoints and implement network segmentation to isolate the Aangine instance from external networks.

Exploitation status

Public Exploit Available: Yes — a published proof-of-concept exists via the GitHub Gist referenced in the CVE record.

Analyst recommendation

This vulnerability presents a clear risk to the confidentiality of organizational data through its unauthenticated attack vector. Administrators should prioritize restricting network access to the affected Aangine services and coordinate with the vendor to apply a patch as soon as it becomes available.

Sources