---
id: CVE-2025-10650
title: "SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys under certain conditions, allowing unauthorized privilege escalation to admin via SSH.\_Affects non-production debug and …"
summary: "SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys under certain conditions, allowing unauthorized privilege escalation to admin via SSH.\_Affects non-production debug and …"
severity: none
cwe:
  - CWE-269
published: '2025-09-18'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-10650'
references:
  - url: 'https://advisories.softiron.cloud/'
    label: 0a72a055-908d-47f5-a16a-1f09049c16c6
tags:
  - nvd
epss: 0.00123
epssPercentile: 0.01785
ingestedAt: '2026-09-30T23:29:32.388Z'
---

## Overview

SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys under certain conditions, allowing unauthorized privilege escalation to admin via SSH. Affects non-production debug and internal development builds created between versions 2.5.0 and 2.6.3.  No generally available (GA) or customer-released production builds were affected.  There is no evidence that this issue was exposed in customer environments or production deployments.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
