logo

MITRE Caldera security suite scores perfect 10 for insecurity

ID: 3fb4555f-3b33-5eca-a0f6-83fd1bdefa5a

STIX ID: report--3fb4555f-3b33-5eca-a0f6-83fd1bdefa5a

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-02-25

Date Updated: 2026-04-26

Author: Connor Jones

...
...

A critical (10/10) unauthenticated remote code execution vulnerability, tracked as CVE-2025-27364, was disclosed in MITRE's Caldera platform affecting all versions before 5.1.0; the flaw allows attackers to trigger RCE via a crafted HTTPS request to an exposed API endpoint when Go, Python, and GCC are installed, and a partial PoC was published—users are advised to apply patches or remove internet/untrusted access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.