CVE-2025-58386

In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper server-side authorization checks. A Power User can intercept and modify this parameter to assign the Administrator role to other existing lower-privileged accounts, or invite a new lower-privileged account and escalate its privileges. While manipulating this request, the Power User can also change the target account's password, effectively taking full control of it.
Configurations

No configuration.

History

03 Dec 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-285

02 Dec 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-02 18:15

Updated : 2025-12-03 16:15


NVD link : CVE-2025-58386

Mitre link : CVE-2025-58386

CVE.ORG link : CVE-2025-58386


JSON object : View

Products Affected

No product.

CWE
CWE-285

Improper Authorization