CVE-2025-12766

An Insecure Direct Object Reference (IDOR) vulnerability in the Management Console of BlackBerry® AtHoc® (OnPrem) version 7.21 could allow an attacker to potentially gain unauthorized knowledge about other organizations hosted on the same Interactive Warning System (IWS).
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:blackberry:athoc:7.21:-:*:*:onprem:*:*:*

History

01 Dec 2025, 17:22

Type Values Removed Values Added
References () https://support.blackberry.com/pkb/s/article/140929 - () https://support.blackberry.com/pkb/s/article/140929 - Vendor Advisory
CPE cpe:2.3:a:blackberry:athoc:7.21:-:*:*:onprem:*:*:*
First Time Blackberry
Blackberry athoc

19 Nov 2025, 18:15

Type Values Removed Values Added
References
  • {'url': 'https://support.blackberry.com/community/s/article/140929', 'source': '[email protected]'}
  • () https://support.blackberry.com/pkb/s/article/140929 -

19 Nov 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-19 17:15

Updated : 2025-12-01 17:22


NVD link : CVE-2025-12766

Mitre link : CVE-2025-12766

CVE.ORG link : CVE-2025-12766


JSON object : View

Products Affected

blackberry

  • athoc
CWE
CWE-639

Authorization Bypass Through User-Controlled Key