The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows account takeover, if SSO is used, when a victim changes the email address that they have configured. To exploit this, an attacker would create their own account and perform an SSO login. The root cause of the issue is SSO misconfiguration.
References
Configurations
No configuration.
History
02 Sep 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-284 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
02 Sep 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-02 16:15
Updated : 2025-09-04 15:36
NVD link : CVE-2025-54599
Mitre link : CVE-2025-54599
CVE.ORG link : CVE-2025-54599
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control