CVE-2025-8866 MEDIUM

CVE-2025-8866

Vendor Yugabytedb Inc
Product YugabyteDB Anywhere
Weakness CWE-200 · Info exposure
Published August 11, 2025
Last update August 11, 2025

CVSS base score

5.1/10
Attack vector Adjacent
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/U:Clear

What the vulnerability does

01Description

YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records.

Key dates

02Disclosure timeline

August 11, 2025 CVE published
August 11, 2025 Record updated