Critical severity9.8NVD Advisory· Published Sep 10, 2025· Updated Jun 17, 2026
CVE-2025-10226
CVE-2025-10226
Description
Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier on Windows and Linux allows a remote attacker to escalate privileges, execute arbitrary code, or cause denial-of-service via exploitation of multiple known CVEs present in PostgreSQL v10.x, which are resolved in PostgreSQL 17.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<=2.0.8+ 1 more
- (no CPE)range: <=2.0.8
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
2- www.axxonsoft.com/legal/axxonsoft-vulnerability-disclosure-policy/security-advisoriesnvdVendor Advisory
- www.postgresql.org/docs/releasenvdRelease Notes
News mentions
0No linked articles in our index yet.