
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-36857 is a broken access control vulnerability (CWE-276: Incorrect Default Permissions) in Rapid7 AppSpider Pro's configuration file loading mechanism. It affects all versions of AppSpider Pro below 7.5.021, allowing standard (low-privileged) users to place custom configuration files into directories belonging to other users or projects. Because configuration files are loaded in alphabetical order, a malicious file can override or alter the settings of legitimate configuration files. The vulnerability was disclosed on September 25, 2025, and carries a CVSS v3.1 base score of 3.3 (Low) (Rapid7 Release Notes, ENISA EUVD).
The root cause is improper directory access management (CWE-276: Incorrect Default Permissions), where the application fails to enforce adequate access controls on configuration file directories. Standard users are permitted to write custom configuration files into directories that should be restricted to other users or projects. Because AppSpider Pro loads configuration files in alphabetical order, an attacker can craft a filename that sorts before the legitimate configuration file, causing their malicious settings to take precedence and override the original configuration. Exploitation requires local access and low-level privileges on the affected system; no network-based attack vector exists (Rapid7 Release Notes, ENISA EUVD).
Successful exploitation allows a low-privileged local attacker to manipulate application configuration settings for other users or projects within AppSpider Pro, compromising the integrity of scan configurations. This could result in unauthorized changes to scan behavior, potentially causing scans to target unintended systems, suppress findings, or alter security testing parameters. There is no direct confidentiality or availability impact (CVSS scores both as None), and the scope is limited to the local system without evidence of lateral movement potential (ENISA EUVD).
There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been observed. The EPSS score is approximately 0.011% (0.000110), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access with at least standard user privileges, significantly limiting the attacker pool (ENISA EUVD).
Rapid7 remediated this vulnerability in AppSpider Pro version 7.5.021, released September 11, 2025, which includes improved scan data directory permission policies and validation, as well as enhanced scan configuration validation to prevent duplicate names and directory conflict handling. Organizations should upgrade to version 7.5.021 or later immediately. As interim workarounds, administrators should implement strict OS-level access controls on AppSpider Pro configuration directories, limit standard user write permissions to only their own directories, and regularly audit file permissions and configuration directories for unauthorized files (Rapid7 Release Notes).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."