CVE-2025-11446 HIGH

CVE-2025-11446

Vendor Upkeeper Solutions
Product upKeeper Manager
Weakness CWE-532 · Sensitive info in logs
Published November 19, 2025
Last update November 19, 2025

CVSS base score

7.3/10
Attack vector Local
Attack complexity High
Privileges required High
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

What the vulnerability does

01Description

Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain Credentials.This issue affects upKeeper Manager: from 5.2.0 before 5.2.12.

Key dates

02Disclosure timeline

November 19, 2025 CVE published
November 19, 2025 Record updated