# Fudo Enterprise versions 5.5.0-5.6.2 contain an access control flaw allowing…

Published: 2026-04-20 · Severity: high
Canonical: https://vorant.io/reports/dfa62423-fa79-407a-bef0-720a7a89d95c/fudo-enterprise-versions-5-5-0-5-6-2-contain-an-access-control-flaw-allowing

> Fudo Enterprise versions 5.5.0-5.6.2 contain an access control flaw allowing low-privileged users to access admin resources including system logs and configuration via unprotected API endpoints.

CERT Polska coordinated the disclosure of CVE-2025-13480, a privilege escalation vulnerability in Fudo Enterprise privileged access management software. The flaw affects versions 5.5.0 through 5.6.2 and stems from improperly protected API endpoints that fail to enforce authorization checks. Low-privileged authenticated users can exploit these endpoints to access administrator-only resources, including sensitive system logs and configuration settings that should be restricted to privileged accounts.

The vulnerability represents a broken access control issue that could allow malicious insiders or compromised low-privilege accounts to gather intelligence about the PAM deployment, potentially facilitating lateral movement or further attacks. Fudo Security reported the vulnerability through CERT Polska's coordinated vulnerability disclosure program, and a patch has been released in version 5.6.3. Organizations running affected versions should prioritize upgrading to remediate this access control bypass.

## Mentioned in this report

- Vulnerabilities: CVE-2025-13480

Source reporting: https://cert.pl/en/posts/2026/04/CVE-2025-13480

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/dfa62423-fa79-407a-bef0-720a7a89d95c/fudo-enterprise-versions-5-5-0-5-6-2-contain-an-access-control-flaw-allowing.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
