CVE-2025-29556 – ExaGrid EX10 Incorrect Access Control Bypass

The following table lists the changes that have been made to the
CVE-2025-29556 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jul. 31, 2025

    Action Type Old Value New Value
    Added Description ExaGrid EX10 6.3 – 7.0.1.P08 is vulnerable to Incorrect Access Control. Since version 6.3, ExaGrid enforces restrictions preventing users with the Admin role from creating or modifying users with the Security Officer role without approval. However, a flaw in the account creation process allows an attacker to bypass these restrictions via API request manipulation. An attacker with an Admin access can intercept and modify the API request during user creation, altering the parameters to assign the new account to the ExaGrid Security Officers group without the required approval.
    Added Reference https://github.com/0xsu3ks/CVE-2025-29556
    Added Reference https://www.exagrid.com/
Share the Post:

Related Posts