CVE-2025-10650

CVSS

No CVSS.

S

oftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys under certain conditions, allowing unauthorized privilege escalation to admin via SSH. Affects non-production debug and internal development builds created between versions 2.5.0 and 2.6.3.  No generally available (GA) or customer-released production builds were affected.  There is no evidence that this issue was exposed in customer environments or production deployments.

References
Configurations

No configuration.

History

20 Feb 2026, 17:25

Type Values Removed Values Added
Summary (en) SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys under certain conditions, allowing unauthorized privilege escalation to admin via SSH. (en) SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys under certain conditions, allowing unauthorized privilege escalation to admin via SSH. Affects non-production debug and internal development builds created between versions 2.5.0 and 2.6.3.  No generally available (GA) or customer-released production builds were affected.  There is no evidence that this issue was exposed in customer environments or production deployments.

19 Sep 2025, 16:00

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-18 19:15

Updated : 2026-02-20 17:25


NVD link : CVE-2025-10650

Mitre link : CVE-2025-10650

CVE.ORG link : CVE-2025-10650


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management