CVE-2025-8884
IDOR in VHS Electronic Software's ACE Center
CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
5th
Authorization Bypass Through User-Controlled Key vulnerability in VHS Electronic Software Ltd. Co. ACE Center allows Privilege Abuse, Exploitation of Trusted Identifiers. This issue affects ACE Center: from 3.10.100.1768 before 3.10.161.2255.
| CWE | CWE-639 |
| Vendor | vhs electronic software ltd. co. |
| Product | ace center |
| Published | Oct 20, 2025 |
| Last Updated | Jun 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for vhs electronic software ltd. co. ace center
Be the first to know when new medium vulnerabilities affecting vhs electronic software ltd. co. ace center are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
VHS Electronic Software Ltd. Co. / ACE Center
3.10.100.1768 < 3.10.161.2255
References
Credits
Can Nesimi ARI