CVE-2025-49825 PUBLISHED

Teleport allows remote authentication bypass

Assigner: GitHub_M
Reserved: 11.06.2025 Published: 17.06.2025 Updated: 18.06.2025

Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 are vulnerable to remote authentication bypass. At time of posting, there is no available open-source patch.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor gravitational
Product teleport
Versions
  • Version <= 17.5.1 is affected
  • Version <= 0.0.0-20250616162021-79b2f26125a1 is affected

References

Problem Types

  • CWE-863: Incorrect Authorization CWE