Improper access control allows arbitrary account creation
Vulnerability Description
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-49652
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Esteban Tonglet
Affected Vendor
Lablup
View all reports →