CVE-2025-56467

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue was discovered in AXIS BANK LIMITED Axis Mobile App 9.9 that allows attackers to obtain sensitive information without a UPI PIN, such as account information, balances, transaction history, and unspecified other information. NOTE: the Supplier's perspective is that this is an intended feature and "does not reveal much sensitive information."

Published 2025-09-12. Last modified 2026-07-05.