Security Advisory

CVE-2025-10226

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-09-10 12:38:42
Last updated 2025-10-08 11:56:42
Assigner AxxonSoft
CVSS score 9.8
State PUBLISHED

Description

Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier on Windows and Linux allows a remote attacker to escalate privileges, execute arbitrary code, or cause denial-of-service via exploitation of multiple known CVEs present in PostgreSQL v10.x, which are resolved in PostgreSQL 17.4.