CVE-2025-25450: Mytaag

Medium severity, CVSS 5.1. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to escalate privileges via the deactivation of the activated second factor to the /session endpoint

Affected products

  • Mytaag Mytaag: up to and including 2024-11-24

Published 2025-03-06. Last modified 2026-06-17.