CVE-2025-49825
Last modified
CVE-2025-49825 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 are vulnerable to remote authentication bypass. EPSS estimates a 7.75% chance of exploitation in the next 30 days.
Description
Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 are vulnerable to remote authentication bypass. At time of posting, there is no available open-source patch.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-49825?
How severe is CVE-2025-49825?
How do I fix CVE-2025-49825?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-49819Rejected reason: Not used
- CVE-2025-49820Rejected reason: Not used
- CVE-2025-49821Rejected reason: Not used
- CVE-2025-49822Rejected reason: Not used
- CVE-2025-49823(conda) Constructor is a tool which allows constructing an i…0
- CVE-2025-49824conda-smithy is a tool for combining a conda recipe with con…1.7
- CVE-2025-49826Next.js is a React framework for building full-stack web app…7.5
- CVE-2025-49827Conjur provides secrets management and application identity …9.8
- CVE-2025-49828Conjur provides secrets management and application identity …8.8
- CVE-2025-49829Conjur provides secrets management and application identity …6.5
- CVE-2025-4983A stored Cross-site Scripting (XSS) vulnerability affecting …8.7
- CVE-2025-49830Conjur provides secrets management and application identity …6.5
Are you affected by CVE-2025-49825?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
