---
id: CVE-2025-14272
title: "A security issue was\_identified\_in Pavilion due to improper\_authorization\_enforcement in API endpoints.\_This vulnerability can\_allow an unauthorized actor to execute privileged operations, including user/role management and other adminis…"
summary: "A security issue was\_identified\_in Pavilion due to improper\_authorization\_enforcement in API endpoints.\_This vulnerability can\_allow an unauthorized actor to execute privileged operations, including user/role management and other adminis…"
severity: none
cwe:
  - CWE-862
published: '2026-06-16'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:10:00.190'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14272'
references:
  - url: >-
      https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1777.html
    label: PSIRT@rockwellautomation.com
tags:
  - nvd
epss: 0.00235
epssPercentile: 0.12994
ingestedAt: '2026-09-30T21:25:07.750Z'
---

## Overview

A security issue was identified in Pavilion due to improper authorization enforcement in API endpoints. This vulnerability can allow an unauthorized actor to execute privileged operations, including user/role management and other administrative actions.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
