
Our researcher logged into an MDM console as a user with zero UI permissions and walked out with developer access to every managed phone in the fleet. Two GETs. CVE-2025-1415 + CVE-2025-1416 in Proget MDM. https://afine.com/blogs/broken-access-control-in-the-real-world-chaining-two-bugs-to-extract-mdm-service-passwords
Post summary
A researcher disclosed that by chaining two CVEs (2025‑1415 and 2025‑1416) in Proget MDM, a zero‑UI user could gain developer access to all devices. No PoC code, patch, or detailed technical breakdown is provided.
