CVE-2025-0640: Akinsoft Octocloud

Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.

Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft OctoCloud allows Resource Leak Exposure. This issue affects OctoCloud: from s1.09.02 before v1.11.01.

Affected products

  • Akinsoft Octocloud: from s1.09.02, before v1.11.01 (fixed in v1.11.01)

Published 2025-09-02. Last modified 2026-09-30.