NONE · 0

CVE-2025-8866

YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking confi...

Vulnerability Description

YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-8866?

CVE-2025-8866 is a documented vulnerability. YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking confi...

How severe is CVE-2025-8866?

CVSS scoring is not yet available for CVE-2025-8866. Check NVD for updates.

Is there a patch for CVE-2025-8866?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.