CVE-2025-59133: Projectopia Custom Role IDOR Vulnerability (7.5 CVSS)
Projectopia versions 5.1.25.2 and earlier contain a flaw that allows attackers to view information they shouldn't have access to by manipulating how the application identifies custom user roles. An unauthenticated attacker can exploit this over the network without user interaction, potentially exposing sensitive data by directly referencing resources assigned to other roles.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Weaknesses (CWE)
- CWE-639
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-15 / 2026-06-17
NVD description (verbatim)
Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2025-59133 is an Insecure Direct Object Reference (IDOR) vulnerability affecting Projectopia's custom role implementation (CWE-639). The flaw permits an unauthenticated, remote attacker to enumerate and access resources by directly manipulating object references associated with custom roles. The attack requires no special privileges, no user interaction, and no special network conditions. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) reflects a high-confidence confidentiality breach with no impact on system integrity or availability.
Business impact
Unauthorized disclosure of sensitive project data, customer information, or business intelligence tied to role-based access controls could harm competitive standing, trigger regulatory compliance failures (GDPR, HIPAA, SOC 2), erode customer trust, and create litigation exposure. The impact scope depends on what data Projectopia stores and which roles are targeted by attackers.
Affected systems
Projectopia versions up to and including 5.1.25.2 are vulnerable. Organizations running these versions in production environments face immediate risk. Verify your installed version via the Projectopia dashboard or administrative interface. The vendor and product list is not populated in the advisory data; consult the official Projectopia security bulletin for definitive version and deployment guidance.
Exploitability
This vulnerability is remotely exploitable without authentication. An attacker can craft requests targeting custom role identifiers from outside your network, making exploitation trivial. No KEV entry has been assigned, indicating that while the threat is well-understood, active exploitation in the wild has not yet been formally cataloged by CISA. Nevertheless, the low attack complexity and lack of privilege requirements mean that exploitation risk is high and weaponization is straightforward.
Remediation
Upgrade Projectopia to a patched version released after 5.1.25.2. Consult the official Projectopia release notes and security advisory to confirm the minimum safe version. Until patching is complete, implement network segmentation to restrict Projectopia access to trusted users, monitor for suspicious role-enumeration requests, and audit custom role assignments for unauthorized access patterns.
Patch guidance
Check Projectopia's official security advisory and release notes for the minimum patched version. Test the upgrade in a non-production environment first, paying attention to any breaking changes in the custom role system. Coordinate the deployment during a scheduled maintenance window to avoid disrupting dependent services. After upgrade, validate that custom roles function as expected and that access controls are properly enforced.
Detection guidance
Monitor HTTP/API logs for repeated attempts to access custom role resources with sequential or enumerated identifiers (e.g., /api/roles/1, /api/roles/2, etc.) from unauthenticated sessions. Alert on 400/403 errors that spike in frequency, as they may indicate IDOR probing. Audit Projectopia's access logs for role-based data exfiltration patterns. If available, enable verbose logging for custom role queries and correlate them with user identity.
Why prioritize this
The HIGH CVSS score (7.5) combined with unauthenticated remote exploitability makes this a priority patch. Although not yet on the KEV catalog, the technical simplicity of exploitation and the direct impact on confidentiality demand rapid remediation. Organizations should target this for patching within 72–96 hours, especially if Projectopia holds PII, financial data, or trade secrets.
Risk score, explained
CVSS 7.5 reflects a remote, unauthenticated attack vector (AV:N/PR:N/UI:N) with no prerequisites for successful exploitation, coupled with high confidentiality impact (C:H). The absence of integrity or availability impact prevents a 'critical' rating, but the ease of exploitation and potential for wide-scale data exposure justify the HIGH severity classification.
Frequently asked questions
What versions of Projectopia are affected?
Projectopia versions 5.1.25.2 and earlier are vulnerable. Verify your version in the application settings or contact your deployment administrator. The advisory does not specify which versions after 5.1.25.2 are patched; consult Projectopia's official release notes.
Can this vulnerability be exploited without internet access?
No. CVE-2025-59133 requires network connectivity to reach the Projectopia instance. If your deployment is air-gapped or firewalled to trusted networks only, risk is materially reduced. However, internal attackers or compromised systems on your network can still exploit it.
Is there a workaround if we cannot patch immediately?
Partial mitigation includes disabling custom roles if operationally feasible, restricting network access to Projectopia to only authenticated VPN or IP-whitelisted clients, and deploying a WAF rule to block role-enumeration patterns. These do not eliminate risk and are temporary measures only.
Has this vulnerability been actively exploited?
As of the publication date, no KEV entry has been assigned and active exploitation has not been formally confirmed by CISA. However, the low complexity of the attack and public availability of this advisory mean that attackers may begin scanning and testing within days. Do not delay patching.
This analysis is provided for informational purposes and does not constitute legal or professional security advice. All version numbers, patch references, and remediation guidance must be validated against official Projectopia security bulletins and release notes before implementation. The absence of a KEV entry does not guarantee the absence of active exploitation. Organizations are advised to conduct independent risk assessment and testing in non-production environments before applying any patches or mitigations. SEC.co assumes no liability for application of this guidance to specific environments. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2025-14772HIGHABB T-MAC Plus Authorization Bypass (CVSS 8.8)
- CVE-2026-12204HIGHShopXO Authorization Bypass in Order & Payment Processing
- CVE-2026-41084HIGHApache Airflow Task Instances API Authorization Bypass
- CVE-2026-42863HIGHFlowiseAI Mass Assignment Vulnerability in Chatflow Update Endpoint
- CVE-2026-42947HIGHNaxclow Device Takeover Vulnerability – Silent Unauthorized Reassignment
- CVE-2026-44692HIGHSharp Laravel Package Authenticated Path Traversal and Unauthorized File Disclosure
- CVE-2026-45281HIGHNextcloud Calendar Authorization Bypass – Patched in 32.0.9 and 33.0.3
- CVE-2026-45743HIGHTermix Authorization Bypass in SSH File Manager