CVE-2025-70363: Ibexa Ez Platform
High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access sensitive data via enumerating object IDs.
Affected products
- Ibexa Ez Platform: from 2.0.0, up to and including 2.5.32
Published 2026-03-06. Last modified 2026-07-05.