CVE-2026-25729
EUVD-2026-557906.02.2026, 21:16
DeepAudit is a multi-agent system for code vulnerability discovery. In 3.0.4 and earlier, there is an improper access control vulnerability in the /api/v1/users/ endpoint allows any authenticated user to enumerate all users in the system and retrieve sensitive information including email addresses, phone numbers, full names, and role information.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| lintsinghua | deepaudit | 𝑥 ≤ 3.0.4 |
𝑥
= Vulnerable software versions