CVE-2025-46826: Insagenda Insa-Auth
Low severity, CVSS 1.3. EPSS: 0.5% chance of exploitation in the next 30 days.
insa-auth is an authentication server for INSA Rouen. A minor issue allowed third-party websites to access the server's secondary authentication bridge, potentially revealing basic student information (name and number). However, the issue posed minimal risk, was never exploited, and had limited impact. A fix was implemented promptly on May 3, 2025.
Affected products
- Insagenda Insa-Auth: before 2025-05-03 (fixed in 2025-05-03)
Published 2025-05-07. Last modified 2026-06-17.