Back to search
CVE-2025-66573
Published: Dec 4, 2025
Modified: May 28, 2026
PUBLISHED
Description
Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product details, and display name. Unauthorized users can extract live session information by accessing this endpoint without authentication.
| Vendor | Product | Versions |
|---|---|---|
mersive | Solstice Pod API | affected 5.5affected 6.2 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now