
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59895 is a remote denial-of-service (DoS) vulnerability affecting the configuration restore functionality of Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18, both developed by Flexense. The vulnerability stems from insufficient validation of user-supplied data during the configuration restore process, allowing unauthenticated remote attackers to corrupt the application's configuration file and render the service unresponsive. It was published on January 28, 2026, and assigned by INCIBE. The CVSS v3.1 base score is 7.5 (High), and the CVSS v4.0 base score is 8.2 (High) (Feedly, INCIBE Advisory).
The root cause is classified as CWE-20 (Improper Input Validation). The vulnerability exists in the configuration restore functionality of the affected Flexense products, where user-supplied data is not adequately validated or sanitized before being used to modify the application's configuration file. An unauthenticated remote attacker can send maliciously crafted network requests to the configuration restore endpoint, causing the configuration file to become corrupted. Once corrupted, the service becomes unresponsive and cannot be restarted even manually, potentially requiring a complete reinstallation of the application (Feedly, INCIBE Advisory).
Successful exploitation results in a complete loss of availability for the affected service — the application becomes unresponsive and the corrupted configuration prevents automatic or manual recovery. In the worst case, a full reinstallation of Sync Breeze Enterprise Server or Disk Pulse Enterprise is required to restore functionality. There is no confidentiality or integrity impact on data, but the persistent nature of the configuration corruption makes this a particularly disruptive DoS condition for enterprise environments relying on these file synchronization and disk monitoring services (Feedly).
There is currently no public proof-of-concept exploit code and no evidence of in-the-wild exploitation (Feedly). No threat actor attribution has been reported. The EPSS score is approximately 0.085%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the unauthenticated, network-accessible attack vector (no privileges or user interaction required) lowers the barrier for exploitation if the service is exposed to untrusted networks (Feedly).
No vendor patch has been publicly announced for v10.4.18 as of the time of this report; users should contact Flexense directly for guidance on available updates or workarounds (Feedly, INCIBE Advisory). Recommended interim mitigations include: restricting network access to the configuration restore functionality to trusted IP addresses only using firewall rules; disabling the configuration restore feature if it is not actively required; implementing input validation and monitoring for suspicious restore activity; and maintaining regular backups of configuration files to enable rapid recovery in the event of corruption.
The vulnerability was assigned and disclosed by INCIBE (Spain's National Cybersecurity Institute) as part of a notice covering multiple vulnerabilities in Flexense products (INCIBE Advisory). No significant public researcher commentary, vendor statements beyond the advisory, or notable media coverage has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."