CVE-2025-66385: Cerebrate-Project Cerebrate

Critical severity, CVSS 9.4. EPSS: 0.4% chance of exploitation in the next 30 days.

UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a higher role such as admin) via the user-edit endpoint by supplying or modifying role_id or organisation_id fields in the edit request.

Affected products

Published 2025-11-28. Last modified 2026-06-17.