
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-49088 is an Improper Input Validation vulnerability (CWE-617: Reachable Assertion) in the OTJ (One Touch Join) service of Pexip Infinity, affecting versions 32.0 through 37.1 before 37.2. The flaw is present only in certain configurations of OTJ for Teams SIP Guest Join, and allows a remote unauthenticated attacker to trigger a software abort via a crafted calendar invite, resulting in denial of service. It was published on December 25, 2025, with a patch available in version 37.2. It carries a CVSS v3.1 base score of 5.9 (Medium) (Pexip Security Bulletins, Red Hat CVE).
The root cause is a reachable assertion (CWE-617) in the OTJ service's input validation logic, which fails to properly sanitize or validate incoming calendar invite data when OTJ for Teams SIP Guest Join is enabled. An attacker can send a specially crafted calendar invite over the network, causing the OTJ service to hit an internal assertion and abort, disrupting service availability. Exploitation requires high attack complexity (AC:H), no privileges, and no user interaction, suggesting the crafted input must meet specific conditions to trigger the abort. No public proof-of-concept or technical write-up detailing the exact payload structure has been identified (Pexip Security Bulletins, Red Hat CVE).
Successful exploitation results in a denial of service by causing the OTJ service to abort, disrupting video conferencing and collaboration capabilities for organizations relying on Pexip Infinity's Teams SIP Guest Join integration. There is no impact on confidentiality or integrity — only availability is affected. The scope is limited to the vulnerable OTJ service component on systems where the specific configuration is enabled (Pexip Security Bulletins).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.139%, reflecting a low probability of exploitation in the near term. No threat actor attribution or CISA KEV catalog listing has been identified for this CVE (Red Hat CVE, ENISA EUVD).
Pexip has released version 37.2 of Pexip Infinity, which addresses this vulnerability. Organizations running versions 32.0 through 37.1 should upgrade to 37.2 or later as the primary remediation. As an interim workaround for systems that cannot be immediately patched, consider disabling OTJ for Teams SIP Guest Join functionality or implementing network-level controls to restrict calendar invite processing to trusted sources (Pexip Security Bulletins).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."