PT-2025-36032 · Unknown · Disclaimersparserimpl.Java

CVE-2025-26454

·

Published

2025-09-01

·

Updated

2025-09-05

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DisclaimersParserImpl.java (affected versions not specified)
Description A flaw exists in the validateUriSchemeAndPermission function within the DisclaimersParserImpl.java component that may allow unauthorized access to data belonging to other users due to a confused deputy condition. Successful exploitation of this issue could result in local privilege escalation without requiring additional execution privileges or user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-299928772
BDU:2025-11689
CVE-2025-26454

Affected Products

Disclaimersparserimpl.Java