{"id":"CVE-2025-65784","title":"Insecure permissions in Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows authenticated attackers with low-level privileges to access other users' information via a crafted API request.","summary":"Insecure permissions in Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows authenticated attackers with low-level privileges to access other users' information via a crafted API request.","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-918"],"vendor":"hubert","product":"hub","affected":["hub = 2.0.1.27.3"],"published":"2026-01-13","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-65784","references":[{"url":"https://github.com/carlos-artmann/vulnerability-research/tree/main/CVE-2025-65784","label":"cve@mitre.org"}],"tags":["nvd"],"epss":0.00351,"epssPercentile":0.28668,"ingestedAt":"2026-07-06T16:44:34.512Z","slug":"CVE-2025-65784","body":"## Overview\n\nInsecure permissions in Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows authenticated attackers with low-level privileges to access other users' information via a crafted API request.\n\n## Affected\n\n- `hub = 2.0.1.27.3`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}