CVE-2025-67796
8.1IKUS · Rdiffweb
IKUS Rdiffweb before 2.10.6 suffers from an improper authorization vulnerability allowing valid access tokens to act as other users.
Executive summary
An improper authorization vulnerability in IKUS Rdiffweb before version 2.10.6 allows authenticated attackers to impersonate other users and access cross-tenant data, creating severe security risks.
Vulnerability
This is an improper authorization vulnerability occurring within the application programming interface, requiring low privileges where an attacker with a valid access token can bypass tenant boundaries.
Business impact
A successful exploit allows malicious actors to read or modify other users data and execute privileged actions across tenants. This leads to severe data compromise and unauthorized access to sensitive organizational information. The CVSS score of 8.1 reflects a high severity level due to the potential for total confidentiality and integrity loss.
Remediation
Immediate Action: Update PyPI package rdiffweb to version 2.10.6 or later immediately.
Proactive Monitoring: Monitor API access logs for anomalous cross-tenant requests and unauthorized user impersonation patterns.
Compensating Controls: Implement strict Web Application Firewall rules to inspect API requests and restrict token usage anomalies if patching is delayed.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Organizations utilizing IKUS Rdiffweb must treat this high-severity authorization flaw with urgency. Apply the vendor security update to version 2.10.6 immediately to eliminate unauthorized cross-tenant data access vectors.