CVE-2025-8306 MEDIUM

CVE-2025-8306: Improper Access Control in Asseco Infomedica Plus

Vendor Asseco
Product InfoMedica Plus
Weakness CWE-1220
Published January 8, 2026
Last update January 8, 2026

CVSS base score

5.1/10
Attack vector Adjacent
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector. A low privileged user is able to obtain encoded passwords of all other accounts (including main administrator) due to lack of granularity in access control.  Chained exploitation of this vulnerability and CVE-2025-8307 allows an attacker to escalate privileges. This vulnerability has been fixed in versions 4.50.1 and 5.38.0

Key dates

02Disclosure timeline

January 8, 2026 CVE published
January 8, 2026 Record updated