CVE-2025-65742: Newgensoft Omnidocs

High severity, CVSS 8.2. EPSS: 0.3% chance of exploitation in the next 30 days.

An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to obtain sensitive information and execute a full account takeover via a crafted API request.

Affected products

Published 2025-12-15. Last modified 2026-10-07.