VORANT. Threat Intelligence Sign in Get the full feed

Fudo Enterprise API flaw exposes admin data

medium vulnerability technology

A vulnerability in Fudo Enterprise lets low-privileged users access admin-only API endpoints, exposing system logs and configuration data.

CERT Polska coordinated disclosure of CVE-2025-13480, a broken access control vulnerability affecting Fudo Enterprise, a privileged access management (PAM) solution, in versions 5.5.0 through 5.6.2. The flaw stems from improperly protected API endpoints that allow low-privileged authenticated users to reach resources intended only for administrators, including sensitive system logs and portions of the system configuration.

Given that Fudo Enterprise is a PAM product used to broker and monitor privileged sessions, exposure of configuration data and logs to non-admin users could aid an attacker in reconnaissance or privilege escalation within an organization's access management infrastructure. The vendor, Fudo Security, reported the issue and has released version 5.6.3 to remediate it. No evidence of active exploitation was mentioned in the advisory.

Mentioned in this report

Vulnerabilities CVE-2025-13480

Source reporting: https://cert.pl/en/posts/2026/04/CVE-2025-13480

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free