Back to search
CVE-2026-25729
Published: Feb 6, 2026
Modified: Feb 6, 2026
PUBLISHED
Description
DeepAudit is a multi-agent system for code vulnerability discovery. In 3.0.4 and earlier, there is an improper access control vulnerability in the /api/v1/users/ endpoint allows any authenticated user to enumerate all users in the system and retrieve sensitive information including email addresses, phone numbers, full names, and role information.
| Vendor | Product | Versions |
|---|---|---|
lintsinghua | DeepAudit | affected <= 3.0.4 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now