{"id":"CVE-2025-65742","title":"An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to obtain sensitive information and execute a full account takeover via a crafted API request.","summary":"An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to obtain sensitive information and execute a full account takeover via a crafted API request.","severity":"high","cvss":8.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","cwe":["CWE-862"],"vendor":"newgensoft","product":"omnidocs","affected":["omnidocs = 11.0"],"published":"2025-12-15","updated":"2026-10-07","sourceUpdated":"2026-10-07T19:10:00.160","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-65742","references":[{"url":"https://github.com/CBx216/CVE-2025-65742-Newgen-OmniDocs-LDAP-BFLA/blob/main/CVE-2025-65742.md","label":"cve@mitre.org"},{"url":"https://newgensoft.com/","label":"cve@mitre.org"}],"tags":["nvd","exploit-available"],"epss":0.00298,"epssPercentile":0.20502,"exploits":{"github":1,"githubRepos":["https://github.com/CBx216/CVE-Newgen-Software-Advisories"],"checkedAt":"2026-10-07T19:44:51.119Z"},"exploitAvailable":true,"ingestedAt":"2026-10-07T19:44:15.690Z","slug":"CVE-2025-65742","body":"## Overview\n\nAn unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to obtain sensitive information and execute a full account takeover via a crafted API request.\n\n## Affected\n\n- `omnidocs = 11.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":57,"depthScoreParts":{"impact":45.1,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}