Authorization bypass in GAMS from GAMS Development Corp.
Vulnerability Description
Vulnerability in the access control system of the GAMS licensing system that allows unlimited valid licenses to be generated, bypassing any usage restrictions. The validator uses an insecure checksum algorithm; knowing this algorithm and the format of the license lines, an attacker can recalculate the checksum and generate a valid license to grant themselves full privileges without credentials or access to the source code, allowing them unrestricted access to GAMS's mathematical models and commercial solvers.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41086
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Juan Embid Sánchez
- Francisco Guerrero Gallardo
Affected Vendor
AMS Development Corp.
View all reports →