CVE-2024-7265: Nask Ezd Rp

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to change the password of any user, including root user, which could lead to privilege escalation. This issue affects EZD RP: from 15 before 15.84, from 16 before 16.15, from 17 before 17.2.

Affected products

  • Nask Ezd Rp: from 15, before 15.84 (fixed in 15.84); from 16, before 16.15 (fixed in 16.15); from 17, before 17.2 (fixed in 17.2)

Published 2024-08-07. Last modified 2026-06-17.