CVE-2025-43904: Medium severity SchedMD Slurm vulnerability
Published Jan 16, 2026
·Updated
In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user to Administrator.
Affected Software
1 affected component
SchedMD Slurm<24.11.5, <24.05.8, <23.11.11
Event History
Jan 16, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-43904?
CVE-2025-43904 has a medium severity level due to the potential unauthorized promotion of users to administrator roles.
2
How do I fix CVE-2025-43904?
To fix CVE-2025-43904, update SchedMD Slurm to version 24.11.5, 24.05.8, or 23.11.11 or later.
3
Who is affected by CVE-2025-43904?
Users of SchedMD Slurm versions prior to 24.11.5, 24.05.8, and 23.11.11 are affected by CVE-2025-43904.
4
What can happen if CVE-2025-43904 is exploited?
Exploitation of CVE-2025-43904 can lead to unauthorized users gaining administrator privileges within the Slurm accounting system.
5
Is CVE-2025-43904 specific to any deployment configurations?
CVE-2025-43904 can occur in any deployment of SchedMD Slurm that allows Coordinator roles to manage user promotions.