CVE-2025-70363: Ibexa Ez Platform

High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access sensitive data via enumerating object IDs.

Affected products

  • Ibexa Ez Platform: from 2.0.0, up to and including 2.5.32

Published 2026-03-06. Last modified 2026-07-05.