Security Advisory

CVE-2025-49652

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-06-09 17:26:20
Last updated 2025-06-11 12:12:18
Assigner HiddenLayer
CVSS score 9.8
State PUBLISHED

Description

Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled.