CVE-2025-59785: 2n Access Commander
High severity, CVSS 7.2. EPSS: 0.2% chance of exploitation in the next 30 days.
Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password policy for backup file encryption. This vulnerability can only be exploited after authenticating with administrator privileges.
Affected products
- 2n Access Commander: before 3.5 (fixed in 3.5)
Published 2026-03-04. Last modified 2026-06-17.