CVE-2025-61075: Adata Mitarbeiter Portal

High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Multiple Incorrect Access Control vulnerabilities in adata Software GmbH Mitarbeiterportal 2.15.2.0 allow remote authenticated, low-privileged users to carry out administrative functions and manipulate data of other users via unauthorized API calls.

Affected products

  • Adata Mitarbeiter Portal: before 2.16.1 (fixed in 2.16.1)

Published 2025-12-09. Last modified 2026-06-17.