Medium severity4.3NVD Advisory· Published Mar 10, 2025· Updated Jun 17, 2026
CVE-2025-27926
CVE-2025-27926
Description
In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) containing passwords that are readable by unauthorized users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:nintex:automation:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:nintex:automation:*:*:*:*:*:*:*:*range: >=5.6,<5.8
- (no CPE)range: 5.6
- Range: <5.8
Patches
Vulnerability mechanics
References
1- help.nintex.com/en-US/platform/ReleaseNotes/K2Five.htmnvdRelease Notes
News mentions
0No linked articles in our index yet.