CVE-2023-25780: Status Powerbpm

Medium severity, CVSS 5.7. EPSS: 0.3% chance of exploitation in the next 30 days.

It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A LAN attacker with normal user privilege can exploit this vulnerability to modify substitute agent to arbitrary users, resulting in serious consequence.

Affected products

  • Status Powerbpm: version 2.0 only

Published 2023-06-02. Last modified 2026-06-17.