CVE-2025-23408: Apache Fineract

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Weak Password Requirements vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.10.1. The issue is fixed in version 1.11.0. Users are encouraged to upgrade to version 1.13.0, the latest release.

Affected products

  • Apache Fineract: before 1.11.0 (fixed in 1.11.0)

Published 2025-12-12. Last modified 2026-10-07.