Vulnerability Description
An Insecure Direct Object Reference (IDOR) vulnerability in the Management Console of BlackBerry® AtHoc® (OnPrem) version 7.21 could allow an attacker to potentially gain unauthorized knowledge about other organizations hosted on the same Interactive Warning System (IWS).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Blackberry | Athoc | 7.21 |
Related Weaknesses (CWE)
References
- https://support.blackberry.com/pkb/s/article/140929Vendor Advisory
FAQ
What is CVE-2025-12766?
CVE-2025-12766 is a vulnerability with a CVSS score of 5.0 (MEDIUM). An Insecure Direct Object Reference (IDOR) vulnerability in the Management Console of BlackBerry® AtHoc® (OnPrem) version 7.21 could allow an attacker to potentially gain unauthorized knowledge about ...
How severe is CVE-2025-12766?
CVE-2025-12766 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-12766?
Check the references section above for vendor advisories and patch information. Affected products include: Blackberry Athoc.