# Asseco mMedica versions before 11.9.5 contain an authentication bypass allowing…

Published: 2025-10-28 · Severity: critical · Sectors: healthcare
Canonical: https://vorant.io/reports/e4cc4152-4e57-41a5-9908-7a99f47a85e6/asseco-mmedica-versions-before-11-9-5-contain-an-authentication-bypass-allowing

> Asseco mMedica versions before 11.9.5 contain an authentication bypass allowing unauthenticated attackers to gain full database access with sensitive medical data.

CERT Polska coordinated disclosure of CVE-2025-9313, a critical authentication bypass vulnerability in Asseco Poland S.A.'s mMedica healthcare software. The flaw allows unauthenticated attackers to connect to a publicly accessible database using arbitrary credentials by exploiting a previously authenticated connection from the mmBackup application. Successful exploitation grants full database access containing sensitive patient and medical data.

All mMedica versions prior to 11.9.5 are affected. The vendor has released version 11.9.5 to address the issue and recommends immediate patching. Organizations running vulnerable versions face significant risk of unauthorized access to protected health information and should prioritize remediation.

The vulnerability's public accessibility combined with the authentication bypass mechanism makes it particularly dangerous for healthcare organizations using the platform. No evidence of active exploitation has been reported in the advisory, but the nature of the flaw suggests low exploitation complexity once technical details become widely known.

## Mentioned in this report

- Vulnerabilities: CVE-2025-9313

Source reporting: https://cert.pl/en/posts/2025/10/CVE-2025-9313

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e4cc4152-4e57-41a5-9908-7a99f47a85e6/asseco-mmedica-versions-before-11-9-5-contain-an-authentication-bypass-allowing.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
