CVE-2025-41086

V

ulnerability in the access control system of the GAMS licensing system that allows unlimited valid licenses to be generated, bypassing any usage restrictions. The validator uses an insecure checksum algorithm; knowing this algorithm and the format of the license lines, an attacker can recalculate the checksum and generate a valid license to grant themselves full privileges without credentials or access to the source code, allowing them unrestricted access to GAMS's mathematical models and commercial solvers.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gams:gams:*:*:*:*:*:*:*:*
cpe:2.3:a:gams:gams:*:*:*:*:*:*:*:*

History

03 Feb 2026, 17:19

Type Values Removed Values Added
First Time Gams gams
CPE cpe:2.3:a:gams:access_control_system:*:*:*:*:*:*:*:* cpe:2.3:a:gams:gams:*:*:*:*:*:*:*:*

30 Jan 2026, 19:05

Type Values Removed Values Added
References () https://www.gams.com/latest/docs/RN_51.html - () https://www.gams.com/latest/docs/RN_51.html - Release Notes
References () https://www.incibe.es/en/incibe-cert/notices/aviso/authorization-bypass-gams-gams-development-corp - () https://www.incibe.es/en/incibe-cert/notices/aviso/authorization-bypass-gams-gams-development-corp - Third Party Advisory
First Time Gams
Gams access Control System
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:gams:access_control_system:*:*:*:*:*:*:*:*

02 Dec 2025, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-02 14:16

Updated : 2026-02-03 17:19


NVD link : CVE-2025-41086

Mitre link : CVE-2025-41086

CVE.ORG link : CVE-2025-41086


JSON object : View

Products Affected
CWE
CWE-639

Authorization Bypass Through User-Controlled Key