Database/Control plane, storage & DevOps
Dell CloudLink (CLI escape): A privileged user with a known password escapes the CLI and takes control of the CloudLink
CVSS 9.1CVE-2025-46364Control plane, storage & DevOpscurated
Impact
A privileged user with a known password escapes the CLI and takes control of the CloudLink server. CloudLink is the key manager for encrypted volumes - control of it is control of the data-at-rest keys for everything it protects.
Who can reach it
Network access plus a known privileged credential.
What to do
Upgrade CloudLink to 8.1.1 or later. Appliance upgrade with a service window. Because this is a KMS, also plan key rotation if you cannot rule out prior access - patching does not undo a key compromise.
References
Related entries
- OAuth2-Proxy: skip_auth_routes route matching flawCVE-2025-54576 · OAuth2-ProxyCritical
- Apache Airflow: logout does not invalidate the session JWT, so an intercepted token stays usableCVE-2025-57735 · Apache Airflow (API server JWT session handling on logout)Critical
- HashiCorp Vault: Root-namespace operator with write on sys/audit gains code execution on the Vault hostCVE-2025-6000 · HashiCorp VaultCritical
- Lantronix EDS3000PS serial-to-Ethernet device server: Full bypass of the management-page loginCVE-2025-67039 · Lantronix EDS3000PS serial-to-Ethernet device serverCritical
- Palo Alto PAN-OS: GlobalProtect portal/gateway auth bypassCVE-2026-0257 · Palo Alto PAN-OSCritical
- Grafana MCP Server: caller-controlled X-Grafana-URL header turns grafana_api_request into a full SSRF primitiveCVE-2026-19516 · mcp-grafana (Grafana MCP Server, X-Grafana-URL destination control)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.