{"id":"CVE-2025-58130","title":"Insufficiently Protected Credentials vulnerability in Apache Fineract.\n\nThis issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1.\n\nUsers are encouraged to upgrade to version 1.13.0, the latest release.","summary":"Insufficiently Protected Credentials vulnerability in Apache Fineract.\n\nThis issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1.\n\nUsers are encouraged to upgrade to version 1.13.0, the latest release.","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-522"],"vendor":"apache","product":"fineract","affected":["fineract < 1.12.1"],"patched":["fineract 1.12.1"],"published":"2025-12-12","updated":"2026-10-07","sourceUpdated":"2026-10-07T20:10:01.970","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-58130","references":[{"url":"https://lists.apache.org/thread/d9zpkc86zk265523tfvbr8w7gyr6onoy","label":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2025/12/11/6","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00428,"epssPercentile":0.34944,"ingestedAt":"2026-10-07T20:46:46.899Z","slug":"CVE-2025-58130","body":"## Overview\n\nInsufficiently Protected Credentials vulnerability in Apache Fineract.\n\nThis issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1.\n\nUsers are encouraged to upgrade to version 1.13.0, the latest release.\n\n## Affected\n\n- `fineract < 1.12.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `fineract 1.12.1`","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}