An issue in continuous.software aangine v.2025.2 allows a remote attacker to obtain sensitive information via the excel-integration-service template download module, integration-persistence-service job listing module, portfolio-item-service data retrieval module endpoints
References
| Link | Resource |
|---|---|
| https://aangine.com | Product |
| https://continuous.software/products | Product |
| https://gist.github.com/c4m0uflag3/26fec868b764c4e7314ad246bab01c88 | Third Party Advisory |
Configurations
History
12 Feb 2026, 15:46
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Continuous.software
Continuous.software aangine |
|
| CPE | cpe:2.3:a:continuous.software:aangine:2025.2:*:*:*:*:*:*:* | |
| References | () https://aangine.com - Product | |
| References | () https://continuous.software/products - Product | |
| References | () https://gist.github.com/c4m0uflag3/26fec868b764c4e7314ad246bab01c88 - Third Party Advisory |
26 Jan 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-26 17:16
Updated : 2026-02-12 15:46
NVD link : CVE-2025-67274
Mitre link : CVE-2025-67274
CVE.ORG link : CVE-2025-67274
JSON object : View
Products Affected
continuous.software
- aangine
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
