CVE-2025-68435
Unknown Unknown - Not Provided
Authentication Bypass in Zerobyte API Allows Unauthorized Access

Publication date: 2025-12-17

Last updated on: 2026-03-05

Assigner: GitHub, Inc.

Description
Zerobyte is a backup automation tool Zerobyte versions prior to 0.18.5 and 0.19.0 contain an authentication bypass vulnerability where authentication middleware is not properly applied to API endpoints. This results in certain API endpoints being accessible without valid session credentials. This is dangerous for those who have exposed Zerobyte to be used outside of their internal network. A fix has been applied in both version 0.19.0 and 0.18.5. If immediate upgrade is not possible, restrict network access to the Zerobyte instance to trusted networks only using firewall rules or network segmentation. This is only a temporary mitigation; upgrading is strongly recommended.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-12-17
Last Modified
2026-03-05
Generated
2026-05-27
AI Q&A
2025-12-18
EPSS Evaluated
2026-05-25
NVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
nicotsx zerobyte to 0.18.5 (exc)
nicotsx zerobyte 0.19.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-305 The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability in Zerobyte versions prior to 0.18.5 and 0.19.0 is an authentication bypass where the authentication middleware is not properly applied to some API endpoints. This means certain API endpoints can be accessed without valid session credentials, allowing unauthorized users to interact with the system.


How can this vulnerability impact me? :

The vulnerability can allow unauthorized access to Zerobyte's API endpoints, potentially exposing sensitive backup automation functions to attackers. This is especially dangerous if Zerobyte is exposed outside of a trusted internal network, as attackers could exploit this to compromise data confidentiality and integrity.


What immediate steps should I take to mitigate this vulnerability?

If immediate upgrade to Zerobyte version 0.18.5 or 0.19.0 is not possible, restrict network access to the Zerobyte instance to trusted networks only using firewall rules or network segmentation. Upgrading to a fixed version is strongly recommended as a permanent solution.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart