CVE-2025-2306 | Improper Access Control vulnerability in LIVE CONTRACT
An Improper Access Control vulnerability was
identified in the file download functionality. This vulnerability allows users
to download sensitive documents without authentication, if the URL is known.
The attack
requires the attacker to know the documents UUIDv4.
Conclusion & alert: CVE-2025-2306 is rated Moderate Risk (49.3/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.73%).Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Exploit prediction scoring system (EPSS) score for CVE-2025-2306
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).