CVE-2025-26499 Details
Description
Under heavy system utilization a random race condition can occur during authentication or token refresh operation. This flaw allows one user to be granted a token intended for another user, resulting in impersonation until the session is ended. This flaw cannot be intentionally exploited due to the required concurring action by two users. However, if the event occurs a user would be inadvertently exposed to another user’s system rights and data access.
A race condition vulnerability has been identified in Wind River Studio Developer version 24.11. Under heavy system load, this flaw can occur during authentication or token refresh operations, allowing one user to inadvertently receive a token intended for another user. This misallocation of tokens can lead to unauthorized impersonation until the affected session is terminated. The vulnerability arises from a random race condition that cannot be intentionally exploited, as it requires concurrent actions from two users. However, if it occurs, it exposes the affected user to another user's system rights and data access.
Users experiencing instability issues in Wind River Studio Developer 24.11 are advised to log out and log back in. Wind River has released a patch for this vulnerability in version 25.05 patch 5. Customers should upgrade to this version and apply all updates and patches.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 11, 2025CISA-ADP
Assessed Sep 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2025-26499 | WindRiver | Permission RequiredVendor |
| https://www.windriver.com/security/vulnerability-responses/CVE-2025-26499 | WindRiver | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-270 | Privilege Context Switching Error | WindRiver |
Affected Products
| Product | Versions |
|---|---|
| Wind River Studio Developer | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | WindRiver |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 11, 2025 | New CVE Received | WindRiver |
Volerion