CVE-2025-27926: Nintex Automation
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) containing passwords that are readable by unauthorized users.
Affected products
- Nintex Automation: from 5.6, before 5.8 (fixed in 5.8)
Published 2025-03-10. Last modified 2026-06-17.