PT-2025-7159 · Q Free · Q-Free Maxtime

·

CVE-2025-26370

·

Published

2025-02-12

·

Updated

2025-10-28

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions: Q-Free MaxTime versions 2.11.0 and earlier
Description: A missing authorization issue in maxprofile/user-groups/routes.lua allows an authenticated, low-privileged attacker to remove privileges from user groups via crafted HTTP requests.
Recommendations: For Q-Free MaxTime versions 2.11.0 and earlier, update to a version later than 2.11.0 to resolve the issue. As a temporary workaround, consider restricting access to the maxprofile/user-groups/routes.lua file until a patch is available. Restrict low-privileged users from making HTTP requests to sensitive routes to minimize the risk of exploitation.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-26370

Affected Products

Q-Free Maxtime