CVE-2024-55585: Mops

Critical severity, CVSS 9.0. EPSS: 0.4% chance of exploitation in the next 30 days.

In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, resulting in unrestricted read and write access, as demonstrated by /api/v1/users/resetpassword.

Affected products

  • Mops Mops: up to and including 1.8.618

Published 2025-06-07. Last modified 2026-06-17.