CVE-2025-26201

Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Credential disclosure vulnerability via the /staff route in GreaterWMS <= 2.1.49 allows a remote unauthenticated attackers to bypass authentication and escalate privileges.

Published 2025-02-24. Last modified 2026-07-05.