CVE-2025-57795

Explorance Blue versions prior to 8.14.13 contain an authenticated remote file download vulnerability in a web service component. In default configurations, this flaw can be leveraged to achieve remote code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:explorance:blue:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:43

Type Values Removed Values Added
Summary
  • (es) Las versiones de Explorance Blue anteriores a la 8.14.13 contienen una vulnerabilidad de descarga remota de archivos autenticada en un componente de servicio web. En configuraciones predeterminadas, esta falla puede ser aprovechada para lograr la ejecución remota de código.

05 Feb 2026, 16:58

Type Values Removed Values Added
CPE cpe:2.3:a:explorance:blue:*:*:*:*:*:*:*:*
References () https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2026/MNDT-2026-0004.md - () https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2026/MNDT-2026-0004.md - Third Party Advisory
References () https://online-help.explorance.com/blue/articles/security-advisories-(january-2026) - () https://online-help.explorance.com/blue/articles/security-advisories-(january-2026) - Vendor Advisory
References () https://online-help.explorance.com/blue/articles/security-advisory:-cve-2025-57795 - () https://online-help.explorance.com/blue/articles/security-advisory:-cve-2025-57795 - Vendor Advisory
References () https://www.explorance.com/products/blue - () https://www.explorance.com/products/blue - Product
First Time Explorance
Explorance blue

28 Jan 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.9

28 Jan 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-28 18:16

Updated : 2026-06-17 09:43


NVD link : CVE-2025-57795

Mitre link : CVE-2025-57795

CVE.ORG link : CVE-2025-57795


JSON object : View

Products Affected

explorance

  • blue
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type