CVE-2025-12766: Insecure Direct Object Reference (IDOR) vulnerability in the Management Console of affected versions of BlackBerry AtHoc.
An Insecure Direct Object Reference (IDOR) vulnerability in the Management Console of BlackBerry® AtHoc® (OnPrem) version 7.21 could allow an attacker to potentially gain unauthorized knowledge about other organizations hosted on the same Interactive Warning System (IWS).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12766?
CVE-2025-12766 is rated as a medium severity vulnerability due to its potential for unauthorized data access.
How do I fix CVE-2025-12766?
To mitigate CVE-2025-12766, ensure that your BlackBerry® AtHoc® version is updated to the latest security release provided by BlackBerry.
What systems are affected by CVE-2025-12766?
CVE-2025-12766 affects the Management Console of BlackBerry® AtHoc® version 7.21.
What type of vulnerability is CVE-2025-12766?
CVE-2025-12766 is classified as an Insecure Direct Object Reference (IDOR) vulnerability.
What can an attacker do with CVE-2025-12766?
An attacker exploiting CVE-2025-12766 could potentially gain unauthorized access to sensitive information from other organizations using the same Interactive Warning System.