CVE-2025-41078 - CVE House
Back to Database
Status published High CVE-2025-41078

Multiple vulnerabilities in Viafirma products

Vulnerability Description

Weaknesses in the authorization mechanisms of Viafirma Documents v3.7.129 allow an authenticated user without privileges to list and access other user data, use user creation, modification, and deletion features, and escalate privileges by impersonating other users of the application in the generation and signing of documents.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41078

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Carlos Aguadé Cabañas

Affected Vendor

Affected Software

Viafirma Documents
Vulnerable Versions:
v3.7.129

Timeline

Official Publish: January 12th, 2026
Last Modified: January 12th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)