Description
A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 that could allow an authenticated user with read-only access to account settings to escalate their privileges to Administrator level.
Published: 2026-06-19
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in FlexNet Manager Suite 2025 R1 allows an authenticated user with only read‑only access to account settings to elevate their privileges to Administrator level. The flaw is a classic Improper Access Control (CWE‑284) issue, enabling full control over the system and any hosted applications. Once the attacker has administrative rights, they could modify configuration, install malware, exfiltrate data, or disrupt service. Affected systems The product is Flexera’s FlexNet Manager Suite, specifically version 2025 R1. The build runs on Windows platforms, as indicated by the CPE string. Only this release is mentioned as affected, but any environment deploying FlexNet Manager Suite 2025 R1 should be scrutinized. Risk and exploitability With a CVSS score of 8.7, the vulnerability is high severity. No EPSS score is available, suggesting that public exploitation data is limited or not yet assessed. The flaw is not listed in CISA’s KEV catalog. The likely attack vector requires an authenticated account with read‑only access; an attacker would need to leverage that account to invoke the privilege elevation. Because the attack is local and requires valid credentials, the operational risk is significant in environments where read‑only users exist.

Affected Systems

Flexera FlexNet Manager Suite 2025 R1, deployed on Windows. No other versions are reported as affected.

Risk and Exploitability

With a CVSS score of 8.7, the vulnerability poses a high risk; the EPSS score is currently unavailable, indicating limited public exploitation data, and the flaw is not in the CISA KEV catalog. The likely attack vector is an authenticated read‑only user. The ability to elevate privileges to Administrator level gives an attacker potentially full control over the system, risking confidentiality, integrity, and availability of all data and services managed by FlexNet Manager Suite.

Generated by OpenCVE AI on June 19, 2026 at 20:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Flexera‑supplied patch or upgrade to a version that resolves the privilege‑escalation flaw for FlexNet Manager Suite 2025 R1.
  • Review role‑based access controls and ensure that read‑only user accounts are not granted privileges that could be abused for privilege escalation; adjust permissions accordingly.
  • Monitor security logs for indications of privilege changes or new administrator accounts and configure alerts for any suspicious activity.
  • If a patch is not yet available, contact Flexera security or support for guidance on mitigating the risk in the interim.

Generated by OpenCVE AI on June 19, 2026 at 20:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 19 Jun 2026 18:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 that could allow an authenticated user with read-only access to account settings to escalate their privileges to Administrator level.
Title FlexNet Manager Suite Privilege Escalation Vulnerability
First Time appeared Flexera
Flexera flexnet Manager Suite
Weaknesses CWE-284
CPEs cpe:2.3:a:flexera:flexnet_manager_suite:2025_r1:*:windows:*:*:*:*:*
Vendors & Products Flexera
Flexera flexnet Manager Suite
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Flexera Flexnet Manager Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: flexera

Published:

Updated: 2026-06-19T13:16:28.357Z

Reserved: 2026-03-11T21:28:06.599Z

Link: CVE-2026-4026

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-19T20:30:04Z

Weaknesses