CVE-2025-52389

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows authenticated attackers to access sensitive data for other users via a crafted HTTP request.

Published 2025-09-08. Last modified 2026-06-17.