CVE-2025-66525

Publication date

2025-12-09 14:13:52

Family

Patchstack

State

PUBLISHED

Description

Missing Authorization vulnerability in Elastic Email Elastic Email Sender elastic-email-sender allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elastic Email Sender: from n/a through <= 1.2.20.