CVE-2026-25254

Improper authorization leads to Remote Code Execution via SocketIO interface.

  • Published Sep 22, 2026
  • CVSS 9.8 critical
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-25254 at the National Vulnerability Database