๐Ÿ” CVE Alert

CVE-2025-8855

HIGH 8.1

2FA Expiry Bypass in Optimus Software's Brokerage Automation

CVSS Score
8.1
EPSS Score
0.1%
EPSS Percentile
19th

Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authentication Bypass by Assumed-Immutable Data vulnerability in Optimus Software Brokerage Automation allows Exploiting Trust in Client, Authentication Bypass, Manipulate Registry Information. This issue affects Brokerage Automation: before 1.1.71.

CWE CWE-639 CWE-640 CWE-302
Vendor optimus software
Product brokerage automation
Published Nov 14, 2025
Last Updated Jun 5, 2026
Stay Ahead of the Next One

Get instant alerts for optimus software brokerage automation

Be the first to know when new high vulnerabilities affecting optimus software brokerage automation are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

Optimus Software / Brokerage Automation
0 < 1.1.71

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
usom.gov.tr: https://www.usom.gov.tr/bildirim/tr-25-0396 siberguvenlik.gov.tr: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0396

Credits

Can Nesimi ARI