CVE-2025-35114: Atlassian Agiloft

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Agiloft Release 28 contains several accounts with default credentials that could allow local privilege escalation. The password hash is known for at least one of the accounts and the credentials could be cracked offline. Users should upgrade to Agiloft Release 30.

Affected products

  • Atlassian Agiloft: from 19, before 30 (fixed in 30)

Published 2025-08-26. Last modified 2026-06-17.