---
id: CVE-2025-43784
title: >-
  Improper Access Control vulnerability in Liferay Portal  7.4.0 through
  7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.8, 2024.Q1.1 through
  2024.Q1.12 and 7.4 GA through update 92 allows guest users to obtain object
  entries informat…
summary: >-
  Improper Access Control vulnerability in Liferay Portal  7.4.0 through
  7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.8, 2024.Q1.1 through
  2024.Q1.12 and 7.4 GA through update 92 allows guest users to obtain object
  entries informat…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-863
vendor: liferay
product: digital_experience_platform
affected:
  - 'digital_experience_platform >= 2024.Q1.1, < 2024.Q1.13'
  - 'digital_experience_platform >= 2024.Q2.0, < 2024.Q2.9'
  - digital_experience_platform = 7.4
  - 'liferay_portal >= 7.4.0, < 7.4.3.125'
patched:
  - digital_experience_platform 2024.Q2.9
  - liferay_portal 7.4.3.125
published: '2025-09-10'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-43784'
references:
  - url: >-
      https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-43784
    label: security@liferay.com
tags:
  - nvd
epss: 0.00256
epssPercentile: 0.15332
ingestedAt: '2026-09-26T00:22:39.917Z'
---

## Overview

Improper Access Control vulnerability in Liferay Portal  7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.8, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows guest users to obtain object entries information via the API Builder.

## Affected

- `digital_experience_platform >= 2024.Q1.1, < 2024.Q1.13`
- `digital_experience_platform >= 2024.Q2.0, < 2024.Q2.9`
- `digital_experience_platform = 7.4`
- `liferay_portal >= 7.4.0, < 7.4.3.125`

## Remediation

Upgrade past the affected range:

- `digital_experience_platform 2024.Q2.9`
- `liferay_portal 7.4.3.125`
