CVE-2025-66424

unknown
Published 2025-11-30 · Modified 2025-12-02
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v2
VIR risk

Description

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2025-66424

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed6.0.29-2+deb12u4
debian debianbullseyefixed5.0.33-2+deb11u4
debian debianforkyfixed7.0.40-1
debian debiansidfixed7.0.40-1
debian debiantrixiefixed7.0.30-1+deb13u1

Package impact

EcosystemPackageVulnerableFixed
python PyPItrytond>=7.5.0,<7.6.117.6.11
python PyPItrytond>=6.0.0,<6.0.706.0.70
python PyPItrytond>=7.0.0,<7.0.407.0.40
python PyPItrytond>=7.1.0,<7.4.217.4.21

References

Verify integrity in audit chain (admin only). AS-IS.