CVE-2022-25369

An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists due to a logic issue when determining if the setup phases of the product can be run again. Once an attacker is authenticated as the new admin user they have added, it is possible to upload an executable file and achieve command execution. This is fixed in 9.5.9, 9.6.16, 9.7.8, 9.8.11, 9.9.8, 9.10.18, 9.12.8, and 9.13.0 (and later).
Configurations

No configuration.

History

23 Jan 2026, 19:15

Type Values Removed Values Added
CWE CWE-287
CWE-288
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

23 Jan 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-23 17:16

Updated : 2026-01-26 15:03


NVD link : CVE-2022-25369

Mitre link : CVE-2022-25369

CVE.ORG link : CVE-2022-25369


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication

CWE-288

Authentication Bypass Using an Alternate Path or Channel