VYPR

OpenZiti

by Openziti

CVEs (3)

  • CVE-2025-27501HigMar 3, 2025
    risk 0.56cvss 8.6epss 0.00

    OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint on the admin panel can be accessed without any form of authentication. This endpoint accepts a user-supplied URL parameter to connect to an OpenZiti Controller and performs…

  • CVE-2025-27500HigMar 3, 2025
    risk 0.53cvss 8.2epss 0.00

    OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint(/api/upload) on the admin panel can be accessed without any form of authentication. This endpoint accepts an HTTP POST to upload a file which is then stored on the node and…

  • CVE-2026-58165HigJun 30, 2026
    risk 0.00cvss 8.8epss 0.00

    OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated non-admin identities with fine-grained enrollment management permissions to create enrollments for any identity, including the default administrator, because…