CVE-2025-24989

high-risk
Published 2025-02-19

An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected customers have been notified. This update addressed the registration control bypass. Affected customers have been given instructions on reviewing their sites for potential exploitation and clean up methods. If you've not been notified this vulnerability does not affect you.

Do I need to act?

!
24.6% chance of exploitation in next 30 days
EPSS score — higher than 75% of all CVEs
!
CISA KEV: actively exploited in the wild
On the Known Exploited Vulnerabilities catalog — federal agencies must patch
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.2/10 High
NETWORK / LOW complexity

Affected Products (1)

Affected Vendors

55
/ 100
high-risk
Severity 28/34 · Critical
Exploitability 22/34 · High
Exposure 5/34 · Minimal