DevSecOps Toolkit

CVE record

CVE-2025-67972

MEDIUMCVSS 4.3

Missing Authorization vulnerability in Zoho Mail Zoho ZeptoMail allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Zoho ZeptoMail: from n/a through 3.2.9.

Vulnerability metadata

Published
2026-02-20T10:52:03.430Z
Modified
2026-05-21T03:46:26.320Z
EPSS
Not available
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

References