VYPR

Obsidian Scheduler

by Obsidian

CVEs (1)

  • CVE-2025-56449HigSep 29, 2025
    risk 0.53cvss 8.2epss 0.00

    A security vulnerability was identified in Obsidian Scheduler's REST API 5.0.0 thru 6.3.0. If an account is locked out due to not enrolling in MFA (e.g. after the 7-day enforcement window), the REST API still allows the use of Basic Authentication to authenticate and perform…