{"id":"CVE-2025-70363","title":"Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access sensitive data via enumerating object IDs.","summary":"Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access sensitive data via enumerating object IDs.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-284"],"vendor":"ibexa","product":"ez_platform","affected":["ez_platform >= 2.0.0, <= 2.5.32"],"published":"2026-03-06","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-70363","references":[{"url":"https://gist.github.com/zywsec/a2bd04864895c8fd6d73dcf14a1f7607","label":"cve@mitre.org"}],"tags":["nvd"],"epss":0.0024,"epssPercentile":0.1343,"ingestedAt":"2026-07-06T16:44:34.520Z","slug":"CVE-2025-70363","body":"## Overview\n\nIncorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access sensitive data via enumerating object IDs.\n\n## Affected\n\n- `ez_platform >= 2.0.0, <= 2.5.32`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}