CVE-2025-22956

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

OPSI before 4.3 allows any client to retrieve any ProductPropertyState, including those of other clients. This can lead to privilege escalation if any ProductPropertyState contains a secret only intended to be accessible by a subset of clients. One example of this is a domain join account password for the windomain package.

Published 2025-09-08. Last modified 2026-06-17.