High severity8.1NVD Advisory· Published Dec 9, 2025· Updated Jun 17, 2026
CVE-2025-61075
CVE-2025-61075
Description
Multiple Incorrect Access Control vulnerabilities in adata Software GmbH Mitarbeiterportal 2.15.2.0 allow remote authenticated, low-privileged users to carry out administrative functions and manipulate data of other users via unauthorized API calls.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:adata:mitarbeiter_portal:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:adata:mitarbeiter_portal:*:*:*:*:*:*:*:*range: <2.16.1
- (no CPE)range: = 2.15.2.0
(expand)+ 1 more
- (no CPE)
- (no CPE)range: = 2.15.2.0
Patches
Vulnerability mechanics
References
2- no-sec.net/posts/cve-2025-61075/nvdExploitThird Party Advisory
- www.adata.de/mitarbeiter-portal/nvdProduct
News mentions
0No linked articles in our index yet.