High severity7.8NVD Advisory· Published Jan 6, 2026· Updated Jun 17, 2026
CVE-2025-14026
CVE-2025-14026
Description
Forcepoint One DLP Client, version 23.04.5642 (and possibly newer versions), includes a restricted version of Python 2.5.4 that prevents use of the ctypes library. ctypes is a foreign function interface (FFI) for Python, enabling calls to DLLs/shared libraries, memory allocation, and direct code execution. It was demonstrated that these restrictions could be bypassed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:forcepoint:one_data_loss_prevention:23.04.5642:*:*:*:*:*:*:*
- Range: 23.04.5642 and possibly newer
- Range: 23.11
Patches
Vulnerability mechanics
References
3- kb.cert.org/vuls/id/420440nvdThird Party Advisory
- www.kb.cert.org/vuls/id/420440nvdThird Party Advisory
- support.forcepoint.com/s/article/000042256nvdPermissions Required
News mentions
0No linked articles in our index yet.