PT-2026-2487 · Unknown · Semantic Machines

CVE-2025-66698

·

Published

2026-01-13

·

Updated

2026-01-13

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Semantic machines version 5.4.8
Description An issue allows attackers to bypass authentication by sending a crafted HTTP request to various API endpoints. The attack targets authentication mechanisms within the software. The affected API endpoints are not specified in detail. The request utilizes crafted data to circumvent normal security checks.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-66698

Affected Products

Semantic Machines