CVE-2025-26700 MEDIUM

CVE-2025-26700

Vendor Siber Systems, Inc.
Product RoboForm Password Manager
Weakness CWE-288
Published February 17, 2025
Last update February 18, 2025

CVSS base score

5.2/10
Attack vector Physical
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

What the vulnerability does

01Description

Authentication bypass using an alternate path or channel issue exists in ”RoboForm Password Manager" App for Android versions prior to 9.7.4, which may allow an attacker with access to a device where the application is installed to bypass the lock screen and obtain sensitive information.

Key dates

02Disclosure timeline

February 17, 2025 CVE published
February 18, 2025 Record updated