Fudo Enterprise API flaw exposes admin resources
CVE-2025-13480 in Fudo Enterprise 5.5.0–5.6.2 lets low-privileged users access admin-only API endpoints, exposing system logs and configuration; fixed in 5.6.3.
CERT Polska has disclosed CVE-2025-13480, an improper access control vulnerability in Fudo Enterprise privileged access management software. The flaw affects versions 5.5.0 through 5.6.2 and allows low-privileged authenticated users to access administrator-only resources through improperly protected API endpoints. Exposed data includes sensitive system logs and portions of the system configuration.
The vulnerability was reported to CERT Polska by Fudo Security itself and has been remediated in version 5.6.3. Organizations running affected versions should upgrade immediately to prevent potential privilege escalation and information disclosure by internal threat actors or compromised low-privilege accounts.
This disclosure follows CERT Polska's coordinated vulnerability disclosure process. No active exploitation has been reported, but the nature of the flaw—granting unauthorized access to administrative functions—poses a risk to organizations relying on Fudo Enterprise for privileged access management and session recording.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/04/CVE-2025-13480
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free