CVE-2025-65742: Newgensoft Omnidocs
High severity, CVSS 8.2. EPSS: 0.3% chance of exploitation in the next 30 days.
An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to obtain sensitive information and execute a full account takeover via a crafted API request.
Affected products
- Newgensoft Omnidocs: version 11.0 only
Published 2025-12-15. Last modified 2026-10-07.