CVE-2025-66385: Cerebrate-Project Cerebrate
Critical severity, CVSS 9.4. EPSS: 0.4% chance of exploitation in the next 30 days.
UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a higher role such as admin) via the user-edit endpoint by supplying or modifying role_id or organisation_id fields in the edit request.
Affected products
- Cerebrate-Project Cerebrate: before 1.30 (fixed in 1.30)
Published 2025-11-28. Last modified 2026-06-17.