CVE-2025-58386: Terminalfour

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper server-side authorization checks. A Power User can intercept and modify this parameter to assign the Administrator role to other existing lower-privileged accounts, or invite a new lower-privileged account and escalate its privileges. While manipulating this request, the Power User can also change the target account's password, effectively taking full control of it.

Affected products

  • Terminalfour Terminalfour: from 8.0.0, before 8.4.1.2 (fixed in 8.4.1.2)

Published 2025-12-02. Last modified 2026-06-17.