CVE-2025-68435: Zerobyte has Authentication Bypass by Primary Weakness

Published Dec 17, 2025
·
Updated

Zerobyte is a backup automation tool Zerobyte versions prior to 0.18.5 and 0.19.0 contain an authentication bypass vulnerability where authentication middleware is not properly applied to API endpoints. This results in certain API endpoints being accessible without valid session credentials. This is dangerous for those who have exposed Zerobyte to be used outside of their internal network. A fix has been applied in both version 0.19.0 and 0.18.5. If immediate upgrade is not possible, restrict network access to the Zerobyte instance to trusted networks only using firewall rules or network segmentation. This is only a temporary mitigation; upgrading is strongly recommended.

Affected Software

3 affected components
Zerobyte Zerobyte<0.18.5, >undefined
Nicotsx Zerobyte<0.18.5
Nicotsx Zerobyte=0.19.0-beta1

Event History

Dec 17, 2025
CVE Published
via MITRE·11:10 PM
Data Sourced
via MITRE·11:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-68435?

CVE-2025-68435 has a medium severity rating due to its potential for unauthorized access to certain API endpoints.

2

How do I fix CVE-2025-68435?

To mitigate CVE-2025-68435, update Zerobyte to version 0.18.5 or 0.19.0 or later.

3

What are the consequences of CVE-2025-68435?

CVE-2025-68435 may allow attackers to access sensitive API endpoints without valid authentication, potentially leading to data exposure.

4

Which versions of Zerobyte are affected by CVE-2025-68435?

Zerobyte versions prior to 0.18.5 and 0.19.0 are affected by CVE-2025-68435.

5

Is authentication bypass a common issue in APIs like CVE-2025-68435?

Yes, authentication bypass vulnerabilities like CVE-2025-68435 are common and can severely impact the security of web applications.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203