CVE-2025-9954: Acquia DAM - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2025-105
Published Oct 29, 2025
·Updated
Missing Authorization vulnerability in Drupal Acquia DAM allows Forceful Browsing. This issue affects Acquia DAM: from 0.0.0 before 1.1.5.
Other sources
Missing Authorization vulnerability in Drupal Acquia DAM allows Forceful Browsing.This issue affects Acquia DAM: from 0.0.0 before 1.1.5.
— MITRE
Affected Software
3 affected componentsFixes available
Acquia DAM<1.1.5
composer/drupal/acquia_dam<1.1.5
1.1.5
Acquia Dam Drupal<1.1.5
Remediation
Patch Available
Event History
Oct 29, 2025
CVE Published
via MITRE·11:12 PM
Data Sourced
via MITRE·11:12 PM
DescriptionWeakness
Oct 30, 2025
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 AM
RemedyAffected Software
Advisory Published
via GitHub·12:31 AM
Data Sourced
via GitHub·12:31 AM
DescriptionSeverityWeaknessAffected Software
Feb 28, 57989
Event
via FIRST·03:06 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-9954?
CVE-2025-9954 has a moderate severity due to the potential for unauthorized access through forceful browsing.
2
How do I fix CVE-2025-9954?
To fix CVE-2025-9954, update Acquia DAM to version 1.1.5 or later.
3
What type of vulnerability is CVE-2025-9954?
CVE-2025-9954 is classified as a Missing Authorization vulnerability.
4
What software is affected by CVE-2025-9954?
CVE-2025-9954 affects Acquia DAM versions prior to 1.1.5.
5
Is there a workaround for CVE-2025-9954?
Currently, the recommended solution for CVE-2025-9954 is to apply the available software update.