CVE-2025-14026

Forcepoint One DLP Client, version 23.04.5642 (and possibly newer versions), includes a restricted version of Python 2.5.4 that prevents use of the ctypes library. ctypes is a foreign function interface (FFI) for Python, enabling calls to DLLs/shared libraries, memory allocation, and direct code execution. It was demonstrated that these restrictions could be bypassed.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:forcepoint:one_data_loss_prevention:23.04.5642:*:*:*:*:*:*:*

History

17 Jun 2026, 08:35

Type Values Removed Values Added
Summary
  • (es) Cliente Forcepoint One DLP, versión 23.04.5642 (y posiblemente versiones más recientes), incluye una versión restringida de Python 2.5.4 que impide el uso de la biblioteca ctypes. ctypes es una interfaz de función externa (FFI) para Python, lo que permite llamadas a DLLs/bibliotecas compartidas, asignación de memoria y ejecución directa de código. Se demostró que estas restricciones podrían ser eludidas.

10 Feb 2026, 19:31

Type Values Removed Values Added
CPE cpe:2.3:a:forcepoint:one_data_loss_prevention:23.04.5642:*:*:*:*:*:*:*
First Time Forcepoint one Data Loss Prevention
Forcepoint
References () https://kb.cert.org/vuls/id/420440 - () https://kb.cert.org/vuls/id/420440 - Third Party Advisory
References () https://support.forcepoint.com/s/article/000042256 - () https://support.forcepoint.com/s/article/000042256 - Permissions Required
References () https://www.kb.cert.org/vuls/id/420440 - () https://www.kb.cert.org/vuls/id/420440 - Third Party Advisory
CWE NVD-CWE-noinfo

06 Jan 2026, 17:15

Type Values Removed Values Added
References
  • () https://www.kb.cert.org/vuls/id/420440 -

06 Jan 2026, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

06 Jan 2026, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-06 15:15

Updated : 2026-06-17 08:35


NVD link : CVE-2025-14026

Mitre link : CVE-2025-14026

CVE.ORG link : CVE-2025-14026


JSON object : View

Products Affected

forcepoint

  • one_data_loss_prevention