CVE-2025-8866: Yugabytedb Inc Yugabytedb Anywhere
Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.
YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records.
Affected products
- Yugabytedb Inc Yugabytedb Anywhere: from 2024, before 2025 (fixed in 2025); from 2.20, before 2.21 (fixed in 2.21)
Published 2025-08-11. Last modified 2026-06-17.