References https://nvd.nist.gov/vuln/detail/CVE-2025-4681 https://support.upkeeper.se/hc/en-us/articles/20159882527772-CVE-2025-4681-Improper-Privilege-Management https://access.redhat.com/security/cve/cve-2025-4681 https://cve.imfht.com/detail/CVE-2025-4681?lang=en https://strobes.co/vi/cve/CVE-2025-4681 https://avd.aquasec.com/nvd/2025/cve-2025-4681/ https://db.gcve.eu/vuln/cve-2025-4681 https://cvefeed.io/vuln/detail/CVE-2025-4681 https://vulners.com/cve/CVE-2025-4681 https://www.security-database.com/detail.php?alert=CVE-2025-4681
Related VulnerabilitiesPoCCVE-2026-59177: ESPHome Device Builder <1.0.10 - Unauthenticated Dashboard AccessPoCCVE-2026-81578: PaperCut NG/MF <=26.0.4 - Unauthenticated ConfigEditor Access via Tapestry Complex-DirectPoCCVE-2026-82329: JFrog Artifactory Access Blank Join Key Authentication BypassPoCCVE-2026-86206: N-able N-central - Access Control Bypass via Path Confusion and Forwarded Header SpoofingPoCCVE-2026-86426: LibreNMS <= 26.7.0 - Unauthenticated API AccessPoCgrafana-loki-api-exposure: Grafana Loki - Unauthenticated API Access大华-智慧园区综合管理平台 updateAccessChannelByVisit SQL注入漏洞PoCCVE-2026-7467: Read More & Accordion <= 3.5.7 - Authenticated Privilege EscalationPoCCVE-2025-14998: Branda WordPress plugin - Privilege EscalationPoCCVE-2025-15403: RegistrationMagic <= 6.0.7.1 - Privilege EscalationPoCCVE-2026-11387: SMS Alert – SMS & OTP for WooCommerce - Privilege EscalationPoCCVE-2026-19598: Pods <= 3.3.9 - Unauthenticated Privilege Escalation via pods_admin AJAX RouterPoCCVE-2026-12394: WordPress MemberGlut < 1.1.5 - Unauthenticated Privilege Escalation