CVE-2025-27926
EUVD-2025-782610.03.2025, 23:15
In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) containing passwords that are readable by unauthorized users.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nintex | automation | 5.6 ≤ 𝑥 < 5.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-276 - Incorrect Default PermissionsDuring installation, installed file permissions are set to allow anyone to modify those files.
- CWE-522 - Insufficiently Protected CredentialsThe product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.