
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59894 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18, both developed by Flexense. The flaw arises from the absence of proper CSRF token implementation, allowing an attacker to trick an authenticated user into performing unwanted actions within the application. It was published on January 28, 2026, and assigned by INCIBE. The vulnerability carries a CVSS v3.1 base score of 8.0 (High) and a CVSS v4.0 base score of 8.5 (High) (Feedly, INCIBE Advisory).
The root cause is classified as CWE-352 (Cross-Site Request Forgery), stemming from the lack of anti-CSRF token validation on state-changing HTTP endpoints in both Sync Breeze Enterprise Server and Disk Pulse Enterprise v10.4.18. An attacker can craft a malicious web page or link that, when visited by an authenticated victim, silently submits a POST request to sensitive endpoints such as /delete_all_commands?sid= using the victim's active session. Because the application does not validate a CSRF token, it cannot distinguish between legitimate user-initiated requests and forged cross-origin requests. Exploitation requires the victim to be logged into the application and to interact with attacker-controlled content (e.g., clicking a link or visiting a malicious page) (Feedly, INCIBE Advisory).
Successful exploitation allows an attacker to cause an authenticated user to perform unauthorized actions on their behalf, including deleting all configured commands and potentially modifying system configurations within Sync Breeze Enterprise Server or Disk Pulse Enterprise. This can result in data loss, disruption of automated disk monitoring or synchronization workflows, and compromise of system integrity and availability. While the vulnerability does not directly expose confidential data to the attacker, the high confidentiality, integrity, and availability impact scores reflect the potential for significant operational damage within affected enterprise environments (Feedly).
There is currently no public proof-of-concept exploit code and no evidence of in-the-wild exploitation for CVE-2025-59894. The EPSS score is approximately 0.019% (0.000190), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated victim to interact with attacker-controlled content, limiting the attack surface to targeted social engineering scenarios within organizations using these Flexense products (Feedly).
POST /delete_all_commands?sid=<victim_session_id> or without a session ID if the application relies solely on cookies./delete_all_commands or similar administrative endpoints in the application's web server access logs, particularly from unusual referrer origins or at unexpected times.Referer headers pointing to external or unknown domains.No vendor patch has been confirmed as available at the time of publication for Sync Breeze Enterprise Server and Disk Pulse Enterprise v10.4.18. As interim mitigations, administrators should implement proper CSRF token validation on all state-changing operations (POST, PUT, DELETE requests) if custom deployment allows, and configure SameSite=Strict or SameSite=Lax cookie attributes to restrict cross-site cookie transmission. Users should be advised not to click on unsolicited links while logged into these applications. Organizations should monitor for a patched release from Flexense and apply it promptly upon availability (Feedly, INCIBE Advisory).
The vulnerability was assigned and disclosed by INCIBE (Spain's National Cybersecurity Institute) as part of a notice covering multiple vulnerabilities in Flexense products. No significant public researcher commentary, social media discussion, or major media coverage has been identified for this CVE beyond standard vulnerability database aggregation (INCIBE Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."