Ad

CVE-2025-49825

CRITICAL CVSS 3.1: 9.8 EPSS 11.5%
Updated Jun 18, 2025
Teleport
Parameter Value
CVSS 9.8 (CRITICAL)
Type CWE-863 (Incorrect Authorization)
Vendor Teleport
Public PoC No

Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 are vulnerable to remote authentication bypass. At time of posting, there is no available open-source patch.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1