YugabyteDB Anywhere web server does not properly enforce authentication for...
Vulnerability Description
YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-8866
Credits & Attribution
No credits recorded in the NVD database.
More from YugabyteDB Inc
View All →Affected Vendor
YugabyteDB Inc
View all reports →