CVE-2025-8866 Details
Description
YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records.
An authentication bypass vulnerability has been identified in the YugabyteDB Anywhere web server, specifically within the universe API endpoint of the metamaster service. This flaw allows unauthenticated attackers to access sensitive server networking configuration details, such as private and public IP addresses and DNS records.
Users can upgrade to YugabyteDB Anywhere version 2.20.7.0, 2.23.1.0 or 2024.1.3.0 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 11, 2025CISA-ADP
Assessed Aug 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.yugabyte.com/preview/secure/vulnerability-disclosure-policy/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| YugabyteDB | >= 2.0, <= 2.18.3.0 >= 2.0, <= 2.14.13.0 >= 2.16.7.0 >= 2.18.3.0 >= 2.0, <= 2.17.3.0 >= 2.0, <= 2.13.0.0 >= 2.0, <= 2.14.0.0 |
CPE
Remediation
| |
| YugabyteDB Anywhere | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 11, 2025 | New CVE Received | [email protected] |
Volerion