CVE-2026-41225
Critical
Published: 13 May 2026
Published
13 May 2026
Modified
13 May 2026
KEV Added
—
Patch
—
CVSS Score
9.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS Score
0.0006
20.1th percentile
Risk Priority
18
60% EPSS · 20% KEV · 20% CVSS
Summary
CVE-2026-41225 is a critical-severity Incorrect Use of Privileged APIs (CWE-648) vulnerability. Its CVSS base score is 9.1 (Critical).
Operationally, ranked at the 20.1th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
NVD Description
A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not…
more
evaluated.
Deeper analysisAI
Automated synthesis unavailable for this CVE.
Details
- CWE(s)
Affected Products
—
Software
inferred from references and description; NVD did not file a CPE for this CVE