CVE-2025-8095
Progress OpenEdge vulnerability analysis and mitigation

Overview

CVE-2025-8095 is a cryptographic weakness vulnerability in Progress Software's OpenEdge platform involving the OECH1 prefix encoding scheme. The OECH1 encoding is intended to obfuscate values across the OpenEdge platform but has been identified as cryptographically weak and unsuitable for stored encodings and enterprise applications. Affected versions include OpenEdge 12.2.0–12.2.18 and 12.8.0–12.8.9. The vulnerability was published on April 14, 2026, and carries a CVSS v4.0 base score of 9.1 (Critical) (GitHub Advisory, ENISA EUVD).

Technical details

The root cause is classified as CWE-257 (Storing Passwords in a Recoverable Format): the OECH1 encoding scheme used across the OpenEdge platform is not based on symmetric encryption and can be reversed or brute-forced, making any value encoded with it effectively recoverable by an attacker. Unlike other supported prefix encodings in OpenEdge — which use symmetric encryption — OECH1 provides only obfuscation, not cryptographic protection. An unauthenticated network attacker with access to OECH1-encoded values (e.g., from configuration files, database entries, or intercepted data) can recover the original plaintext without requiring elevated privileges or user interaction (GitHub Advisory, ENISA EUVD).

Impact

Successful exploitation allows an attacker to recover sensitive data — including credentials, passwords, and other protected values — stored or transmitted using OECH1 encoding across the OpenEdge platform. Because the encoding is used platform-wide, the scope of exposure can be broad, potentially affecting authentication credentials that enable lateral movement into connected systems and databases. The CVSS v4.0 scoring reflects high confidentiality, integrity, and availability impact on both the vulnerable and subsequent systems, underscoring the potential for cascading compromise (GitHub Advisory, Feedly).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.023–0.033%, placing it in the lower percentiles for near-term exploitation probability (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack requires no authentication, no user interaction, and has low complexity, making it theoretically automatable at scale if targeted.

Mitigation and workarounds

No software patch is available; remediation requires manual action. Progress Software advises that all OECH1-encoded values should be immediately identified and re-encoded using any other supported OpenEdge prefix encoding, all of which are based on symmetric encryption. Organizations running OpenEdge 12.2.0–12.2.18 or 12.8.0–12.8.9 should audit their configurations, databases, and application settings for any OECH1-prefixed values and replace them as an urgent priority (Progress Community, GitHub Advisory).

Community reactions

The vulnerability received coverage from automated threat intelligence aggregators and security databases shortly after disclosure on April 14, 2026, including entries on VulnDB, CIRCL, and radar.offseq.com (Feedly). A brief technical summary was published by Infinit Security at infinitsec.net. No significant vendor statements beyond the Progress Community advisory or notable researcher commentary have been identified at this time.

Additional resources


SourceThis report was generated using AI

Related Progress OpenEdge vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-8095CRITICAL9.1
  • Progress OpenEdge logoProgress OpenEdge
  • cpe:2.3:a:progress:openedge
NoYesApr 14, 2026
CVE-2025-7388HIGH8.4
  • Progress OpenEdge logoProgress OpenEdge
  • cpe:2.3:a:progress:openedge
NoYesSep 04, 2025
CVE-2025-7389HIGH8.2
  • Progress OpenEdge logoProgress OpenEdge
  • cpe:2.3:a:progress:openedge
NoYesApr 14, 2026
CVE-2024-7654MEDIUM6.1
  • Progress OpenEdge logoProgress OpenEdge
  • cpe:2.3:a:progress:openedge
NoYesSep 03, 2024
CVE-2024-7346MEDIUM4.8
  • Progress OpenEdge logoProgress OpenEdge
  • cpe:2.3:a:progress:openedge
NoYesSep 03, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management