
CVE-2025-8325 The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing i… https://www.cve.org/CVERecord?id=CVE-2025-8325
Post summary
The content discloses a role‑based access control flaw in the Gateway API, where users with the 'Internal/Everyone' role can invoke privileged APIs, without providing PoC, exploit, or patch details.

