ZDI-CAN-26902: ZDI-25-895: (0Day) Wondershare Repairit Incorrect Permission Assignment Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of Wondershare Repairit. Authentication is not required to exploit this vulnerability. The specific flaw exists within the permissions granted to a storage account token. An attacker can leverage this vulnerability to bypass authentication on the system.
Other sources
This vulnerability allows remote attackers to bypass authentication on affected installations of Wondershare Repairit. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.1. The following CVEs are assigned: CVE-2025-10643.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-26902?
The severity of ZDI-CAN-26902 is high due to the ability for remote attackers to bypass authentication.
How do I fix ZDI-CAN-26902?
To fix ZDI-CAN-26902, ensure that permissions for storage account tokens are properly restricted.
Who is affected by ZDI-CAN-26902?
ZDI-CAN-26902 affects installations of Wondershare Repairit that do not have proper security configurations.
Can ZDI-CAN-26902 be exploited remotely?
Yes, ZDI-CAN-26902 can be exploited remotely without any authentication required.
What type of vulnerability is ZDI-CAN-26902?
ZDI-CAN-26902 is an authentication bypass vulnerability.