This page aggregates publicly disclosed CVE and security risk information related to eigentech, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2021-38617 | In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/user/ user creation endpoint allows a standard user to create a super user account with a defined password. This directly leads to privilege escalation. | [email protected] | 8.8 | 0.88% | 2021-09-07 | 2025-05-30 |
| CVE-2021-38616 | In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/user/{user-guid}/ user edition endpoint could permit any logged-in user to increase their own permissions via a user_permissions array in a PATCH request. A guest user could modify other users' profiles and much more. | [email protected] | 7.6 | 0.90% | 2021-09-07 | 2025-05-30 |
| CVE-2021-38615 | In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/sso/config/ SSO configuration endpoint allows any logged-in user (guest, standard, or admin) to view and modify information. | [email protected] | 6.3 | 0.34% | 2021-09-07 | 2025-05-30 |