peter bassill · operator
$ cve CVE-2025-49825 JSON

CVE-2025-49825

9.8
CRITICAL · CVSS 3.1 · EPSS 7.9% (pctl 95)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 are vulnerable to remote authentication bypass. At time of posting, there is no available open-source patch.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.92% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-863
On CISA KEVno
Public exploitnone known
Published2025-06-17
Last modified2026-06-17

References

→ the Explorer  ·  watch your stack  ·  NVD