High severity7.5NVD Advisory· Published Mar 2, 2026· Updated Jun 17, 2026
CVE-2025-58402
CVE-2025-58402
Description
The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks. By modifying the parameter in the GET request, an attacker can access messages and attachments belonging to other users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- cert.pl/en/posts/2026/03/CVE-2025-10350/nvdThird Party Advisory
- www.cgm.com/pol_pl/products/szpital/cgm-clininet.htmlnvdProduct
News mentions
0No linked articles in our index yet.