{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-25741",
        "tracking": {
            "current_release_date": "2026-03-23T09:39:01.360658Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-25741",
            "initial_release_date": "2026-02-26T22:28:01.485584Z",
            "revision_history": [
                {
                    "date": "2026-02-26T22:28:01.485584Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-02-26T22:28:06.721904Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-02-26T22:38:57.277067Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-02-26T22:38:59.151864Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-27T14:37:38.799335Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-02-27T14:37:40.577965Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-28T13:56:03.698803Z",
                    "number": "7",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (77).| Products created (1).| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-03-03T21:39:11.487291Z",
                    "number": "8",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-03T21:39:13.788047Z",
                    "number": "9",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T09:46:32.077239Z",
                    "number": "10",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T09:46:35.569515Z",
                    "number": "11",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "11"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.0",
                                "product": {
                                    "name": "vers:unknown/1.3.0",
                                    "product_id": "CSAFPID-298245"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.1",
                                "product": {
                                    "name": "vers:unknown/1.3.1",
                                    "product_id": "CSAFPID-298225"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.10",
                                "product": {
                                    "name": "vers:unknown/1.3.10",
                                    "product_id": "CSAFPID-298244"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.11",
                                "product": {
                                    "name": "vers:unknown/1.3.11",
                                    "product_id": "CSAFPID-298236"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.12",
                                "product": {
                                    "name": "vers:unknown/1.3.12",
                                    "product_id": "CSAFPID-712508"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.13",
                                "product": {
                                    "name": "vers:unknown/1.3.13",
                                    "product_id": "CSAFPID-712471"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.2",
                                "product": {
                                    "name": "vers:unknown/1.3.2",
                                    "product_id": "CSAFPID-298235"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.3",
                                "product": {
                                    "name": "vers:unknown/1.3.3",
                                    "product_id": "CSAFPID-298237"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.4",
                                "product": {
                                    "name": "vers:unknown/1.3.4",
                                    "product_id": "CSAFPID-298243"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.5",
                                "product": {
                                    "name": "vers:unknown/1.3.5",
                                    "product_id": "CSAFPID-298222"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.6",
                                "product": {
                                    "name": "vers:unknown/1.3.6",
                                    "product_id": "CSAFPID-298231"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.7",
                                "product": {
                                    "name": "vers:unknown/1.3.7",
                                    "product_id": "CSAFPID-298233"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.8",
                                "product": {
                                    "name": "vers:unknown/1.3.8",
                                    "product_id": "CSAFPID-298242"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.9",
                                "product": {
                                    "name": "vers:unknown/1.3.9",
                                    "product_id": "CSAFPID-298246"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.4.0",
                                "product": {
                                    "name": "vers:unknown/1.4.0",
                                    "product_id": "CSAFPID-712505"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.5.0",
                                "product": {
                                    "name": "vers:unknown/1.5.0",
                                    "product_id": "CSAFPID-712490"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.6.0",
                                "product": {
                                    "name": "vers:unknown/1.6.0",
                                    "product_id": "CSAFPID-712520"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.7.0",
                                "product": {
                                    "name": "vers:unknown/1.7.0",
                                    "product_id": "CSAFPID-712509"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.0",
                                "product": {
                                    "name": "vers:unknown/1.8.0",
                                    "product_id": "CSAFPID-712482"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.8.0-rc1",
                                "product": {
                                    "name": "vers:unknown/1.8.0-rc1",
                                    "product_id": "CSAFPID-3352461"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.9.0",
                                "product": {
                                    "name": "vers:unknown/1.9.0",
                                    "product_id": "CSAFPID-712470"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.9.0-rc2",
                                "product": {
                                    "name": "vers:unknown/1.9.0-rc2",
                                    "product_id": "CSAFPID-3352462"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.9.0-rc3",
                                "product": {
                                    "name": "vers:unknown/1.9.0-rc3",
                                    "product_id": "CSAFPID-3352463"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/10.0",
                                "product": {
                                    "name": "vers:unknown/10.0",
                                    "product_id": "CSAFPID-2730837",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:zulip:zulip:10.0:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/10.0-beta1",
                                "product": {
                                    "name": "vers:unknown/10.0-beta1",
                                    "product_id": "CSAFPID-3760070"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/10.0-beta2",
                                "product": {
                                    "name": "vers:unknown/10.0-beta2",
                                    "product_id": "CSAFPID-3760071"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/10.0-dev",
                                "product": {
                                    "name": "vers:unknown/10.0-dev",
                                    "product_id": "CSAFPID-3668202"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/11.0",
                                "product": {
                                    "name": "vers:unknown/11.0",
                                    "product_id": "CSAFPID-5573872"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/11.0-beta1",
                                "product": {
                                    "name": "vers:unknown/11.0-beta1",
                                    "product_id": "CSAFPID-5573873"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/11.0-beta2",
                                "product": {
                                    "name": "vers:unknown/11.0-beta2",
                                    "product_id": "CSAFPID-5573874"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/11.0-dev",
                                "product": {
                                    "name": "vers:unknown/11.0-dev",
                                    "product_id": "CSAFPID-3769087"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/12.0-dev",
                                "product": {
                                    "name": "vers:unknown/12.0-dev",
                                    "product_id": "CSAFPID-5749430"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.0",
                                "product": {
                                    "name": "vers:unknown/2.0.0",
                                    "product_id": "CSAFPID-712467"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.0-rc1",
                                "product": {
                                    "name": "vers:unknown/2.0.0-rc1",
                                    "product_id": "CSAFPID-3352464"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1-dev",
                                "product": {
                                    "name": "vers:unknown/2.1-dev",
                                    "product_id": "CSAFPID-3352465"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1.0",
                                "product": {
                                    "name": "vers:unknown/2.1.0",
                                    "product_id": "CSAFPID-712474"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1.0-rc1",
                                "product": {
                                    "name": "vers:unknown/2.1.0-rc1",
                                    "product_id": "CSAFPID-3631470"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.2-dev",
                                "product": {
                                    "name": "vers:unknown/2.2-dev",
                                    "product_id": "CSAFPID-3631471"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0",
                                "product": {
                                    "name": "vers:unknown/3.0",
                                    "product_id": "CSAFPID-712493"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0-dev",
                                "product": {
                                    "name": "vers:unknown/3.0-dev",
                                    "product_id": "CSAFPID-3631472"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0-rc1",
                                "product": {
                                    "name": "vers:unknown/3.0-rc1",
                                    "product_id": "CSAFPID-3631473"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0-rc2",
                                "product": {
                                    "name": "vers:unknown/3.0-rc2",
                                    "product_id": "CSAFPID-3631474"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.0",
                                "product": {
                                    "name": "vers:unknown/4.0",
                                    "product_id": "CSAFPID-712492"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.0-dev",
                                "product": {
                                    "name": "vers:unknown/4.0-dev",
                                    "product_id": "CSAFPID-3631475"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0",
                                "product": {
                                    "name": "vers:unknown/5.0",
                                    "product_id": "CSAFPID-814326"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0-dev",
                                "product": {
                                    "name": "vers:unknown/5.0-dev",
                                    "product_id": "CSAFPID-3631476"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/6.0",
                                "product": {
                                    "name": "vers:unknown/6.0",
                                    "product_id": "CSAFPID-3631477"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/6.0-dev",
                                "product": {
                                    "name": "vers:unknown/6.0-dev",
                                    "product_id": "CSAFPID-3631478"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/7.0",
                                "product": {
                                    "name": "vers:unknown/7.0",
                                    "product_id": "CSAFPID-3631479"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/7.0-beta3",
                                "product": {
                                    "name": "vers:unknown/7.0-beta3",
                                    "product_id": "CSAFPID-3631480"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/7.0-dev",
                                "product": {
                                    "name": "vers:unknown/7.0-dev",
                                    "product_id": "CSAFPID-3631481"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.0",
                                "product": {
                                    "name": "vers:unknown/8.0",
                                    "product_id": "CSAFPID-1077241"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.0-beta1",
                                "product": {
                                    "name": "vers:unknown/8.0-beta1",
                                    "product_id": "CSAFPID-3631482"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.0-beta2",
                                "product": {
                                    "name": "vers:unknown/8.0-beta2",
                                    "product_id": "CSAFPID-3631483"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.0-dev",
                                "product": {
                                    "name": "vers:unknown/8.0-dev",
                                    "product_id": "CSAFPID-3631484"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.0",
                                "product": {
                                    "name": "vers:unknown/9.0",
                                    "product_id": "CSAFPID-3668203"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.0-beta1",
                                "product": {
                                    "name": "vers:unknown/9.0-beta1",
                                    "product_id": "CSAFPID-3668204"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/9.0-dev",
                                "product": {
                                    "name": "vers:unknown/9.0-dev",
                                    "product_id": "CSAFPID-3631485"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<bf28c82dc9b1f630fa8e9106358771b20a0040f7",
                                "product": {
                                    "name": "vers:unknown/<bf28c82dc9b1f630fa8e9106358771b20a0040f7",
                                    "product_id": "CSAFPID-5733129"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/enterprise-1.1.5",
                                "product": {
                                    "name": "vers:unknown/enterprise-1.1.5",
                                    "product_id": "CSAFPID-3352466"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/enterprise-1.2.0",
                                "product": {
                                    "name": "vers:unknown/enterprise-1.2.0",
                                    "product_id": "CSAFPID-3352467"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/shared-0.0.1",
                                "product": {
                                    "name": "vers:unknown/shared-0.0.1",
                                    "product_id": "CSAFPID-3352468"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/shared-0.0.10",
                                "product": {
                                    "name": "vers:unknown/shared-0.0.10",
                                    "product_id": "CSAFPID-3631486"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/shared-0.0.11",
                                "product": {
                                    "name": "vers:unknown/shared-0.0.11",
                                    "product_id": "CSAFPID-3631487"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/shared-0.0.12",
                                "product": {
                                    "name": "vers:unknown/shared-0.0.12",
                                    "product_id": "CSAFPID-3631488"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/shared-0.0.13",
                                "product": {
                                    "name": "vers:unknown/shared-0.0.13",
                                    "product_id": "CSAFPID-3631489"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/shared-0.0.14",
                                "product": {
                                    "name": "vers:unknown/shared-0.0.14",
                                    "product_id": "CSAFPID-3631490"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/shared-0.0.15",
                                "product": {
                                    "name": "vers:unknown/shared-0.0.15",
                                    "product_id": "CSAFPID-3631491"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/shared-0.0.16",
                                "product": {
                                    "name": "vers:unknown/shared-0.0.16",
                                    "product_id": "CSAFPID-3631492"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/shared-0.0.17",
                                "product": {
                                    "name": "vers:unknown/shared-0.0.17",
                                    "product_id": "CSAFPID-3631493"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/shared-0.0.18",
                                "product": {
                                    "name": "vers:unknown/shared-0.0.18",
                                    "product_id": "CSAFPID-3631494"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/shared-0.0.2",
                                "product": {
                                    "name": "vers:unknown/shared-0.0.2",
                                    "product_id": "CSAFPID-3352469"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/shared-0.0.3",
                                "product": {
                                    "name": "vers:unknown/shared-0.0.3",
                                    "product_id": "CSAFPID-3631495"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/shared-0.0.4",
                                "product": {
                                    "name": "vers:unknown/shared-0.0.4",
                                    "product_id": "CSAFPID-3631496"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/shared-0.0.5",
                                "product": {
                                    "name": "vers:unknown/shared-0.0.5",
                                    "product_id": "CSAFPID-3631497"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/shared-0.0.6",
                                "product": {
                                    "name": "vers:unknown/shared-0.0.6",
                                    "product_id": "CSAFPID-3631498"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/shared-0.0.7",
                                "product": {
                                    "name": "vers:unknown/shared-0.0.7",
                                    "product_id": "CSAFPID-3631499"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/shared-0.0.8",
                                "product": {
                                    "name": "vers:unknown/shared-0.0.8",
                                    "product_id": "CSAFPID-3631500"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/shared-0.0.9",
                                "product": {
                                    "name": "vers:unknown/shared-0.0.9",
                                    "product_id": "CSAFPID-3631501"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Zulip"
                    }
                ],
                "category": "vendor",
                "name": "Zulip"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-25741",
            "cwe": {
                "id": "CWE-863",
                "name": "Incorrect Authorization"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpoint for creating a card update session during an upgrade flow was accessible to users with only organization member privileges. When the associated Stripe Checkout session is completed, the Stripe webhook updates the organization’s default payment method. Because no billing-specific authorization check is enforced, a regular (non-billing) member can change the organization’s payment method. This vulnerability affected the Zulip Cloud payment processing system, and has been patched as of commit bf28c82dc9b1f630fa8e9106358771b20a0040f7. Self-hosted deploys are no longer affected and no patch or upgrade is required for them.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-25741"
                },
                {
                    "category": "description",
                    "text": "Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpoint for creating a card update session during an upgrade flow was accessible to users with only organization member privileges. When the associated Stripe Checkout session is completed, the Stripe webhook updates the organization’s default payment method. Because no billing-specific authorization check is enforced, a regular (non-billing) member can change the organization’s payment method. This vulnerability affected the Zulip Cloud payment processing system, and has been patched as of commit bf28c82dc9b1f630fa8e9106358771b20a0040f7. Self-hosted deploys are no longer affected and no patch or upgrade is required for them.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-25741"
                },
                {
                    "category": "description",
                    "text": "Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpoint for creating a card update session during an upgrade flow was accessible to users with only organization member privileges. When the associated Stripe Checkout session is completed, the Stripe webhook updates the organization’s default payment method. Because no billing-specific authorization check is enforced, a regular (non-billing) member can change the organization’s payment method. This vulnerability affected the Zulip Cloud payment processing system, and has been patched as of commit bf28c82dc9b1f630fa8e9106358771b20a0040f7. Self-hosted deploys are no longer affected and no patch or upgrade is required for them.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-25741.json?alt=media"
                },
                {
                    "category": "other",
                    "text": "0.0004",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "4.6",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "Is related to CWE-863 (Incorrect Authorization)",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "Is related to (a version of) an uncommon product, There is cwe data available from source Nvd",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5733129",
                    "CSAFPID-298222",
                    "CSAFPID-298225",
                    "CSAFPID-298231",
                    "CSAFPID-298233",
                    "CSAFPID-298235",
                    "CSAFPID-298236",
                    "CSAFPID-298237",
                    "CSAFPID-298242",
                    "CSAFPID-298243",
                    "CSAFPID-298244",
                    "CSAFPID-298245",
                    "CSAFPID-298246",
                    "CSAFPID-712467",
                    "CSAFPID-712470",
                    "CSAFPID-712471",
                    "CSAFPID-712474",
                    "CSAFPID-712482",
                    "CSAFPID-712490",
                    "CSAFPID-712492",
                    "CSAFPID-712493",
                    "CSAFPID-712505",
                    "CSAFPID-712508",
                    "CSAFPID-712509",
                    "CSAFPID-712520",
                    "CSAFPID-814326",
                    "CSAFPID-1077241",
                    "CSAFPID-2730837",
                    "CSAFPID-3352461",
                    "CSAFPID-3352462",
                    "CSAFPID-3352463",
                    "CSAFPID-3352464",
                    "CSAFPID-3352465",
                    "CSAFPID-3352466",
                    "CSAFPID-3352467",
                    "CSAFPID-3352468",
                    "CSAFPID-3352469",
                    "CSAFPID-3631470",
                    "CSAFPID-3631471",
                    "CSAFPID-3631472",
                    "CSAFPID-3631473",
                    "CSAFPID-3631474",
                    "CSAFPID-3631475",
                    "CSAFPID-3631476",
                    "CSAFPID-3631477",
                    "CSAFPID-3631478",
                    "CSAFPID-3631479",
                    "CSAFPID-3631480",
                    "CSAFPID-3631481",
                    "CSAFPID-3631482",
                    "CSAFPID-3631483",
                    "CSAFPID-3631484",
                    "CSAFPID-3631485",
                    "CSAFPID-3631486",
                    "CSAFPID-3631487",
                    "CSAFPID-3631488",
                    "CSAFPID-3631489",
                    "CSAFPID-3631490",
                    "CSAFPID-3631491",
                    "CSAFPID-3631492",
                    "CSAFPID-3631493",
                    "CSAFPID-3631494",
                    "CSAFPID-3631495",
                    "CSAFPID-3631496",
                    "CSAFPID-3631497",
                    "CSAFPID-3631498",
                    "CSAFPID-3631499",
                    "CSAFPID-3631500",
                    "CSAFPID-3631501",
                    "CSAFPID-3668202",
                    "CSAFPID-3668203",
                    "CSAFPID-3668204",
                    "CSAFPID-3760070",
                    "CSAFPID-3760071",
                    "CSAFPID-3769087",
                    "CSAFPID-5573872",
                    "CSAFPID-5573873",
                    "CSAFPID-5573874",
                    "CSAFPID-5749430"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25741"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-25741"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-25741"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/25xxx/CVE-2026-25741.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-25741"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-25741.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "https://github.com/zulip/zulip/commit/bf28c82dc9b1f630fa8e9106358771b20a0040f7"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "https://github.com/zulip/zulip/security/advisories/GHSA-vhhx-84f7-rc8j"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25741.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25741"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L",
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1077241",
                        "CSAFPID-2730837",
                        "CSAFPID-298222",
                        "CSAFPID-298225",
                        "CSAFPID-298231",
                        "CSAFPID-298233",
                        "CSAFPID-298235",
                        "CSAFPID-298236",
                        "CSAFPID-298237",
                        "CSAFPID-298242",
                        "CSAFPID-298243",
                        "CSAFPID-298244",
                        "CSAFPID-298245",
                        "CSAFPID-298246",
                        "CSAFPID-3352461",
                        "CSAFPID-3352462",
                        "CSAFPID-3352463",
                        "CSAFPID-3352464",
                        "CSAFPID-3352465",
                        "CSAFPID-3352466",
                        "CSAFPID-3352467",
                        "CSAFPID-3352468",
                        "CSAFPID-3352469",
                        "CSAFPID-3631470",
                        "CSAFPID-3631471",
                        "CSAFPID-3631472",
                        "CSAFPID-3631473",
                        "CSAFPID-3631474",
                        "CSAFPID-3631475",
                        "CSAFPID-3631476",
                        "CSAFPID-3631477",
                        "CSAFPID-3631478",
                        "CSAFPID-3631479",
                        "CSAFPID-3631480",
                        "CSAFPID-3631481",
                        "CSAFPID-3631482",
                        "CSAFPID-3631483",
                        "CSAFPID-3631484",
                        "CSAFPID-3631485",
                        "CSAFPID-3631486",
                        "CSAFPID-3631487",
                        "CSAFPID-3631488",
                        "CSAFPID-3631489",
                        "CSAFPID-3631490",
                        "CSAFPID-3631491",
                        "CSAFPID-3631492",
                        "CSAFPID-3631493",
                        "CSAFPID-3631494",
                        "CSAFPID-3631495",
                        "CSAFPID-3631496",
                        "CSAFPID-3631497",
                        "CSAFPID-3631498",
                        "CSAFPID-3631499",
                        "CSAFPID-3631500",
                        "CSAFPID-3631501",
                        "CSAFPID-3668202",
                        "CSAFPID-3668203",
                        "CSAFPID-3668204",
                        "CSAFPID-3760070",
                        "CSAFPID-3760071",
                        "CSAFPID-3769087",
                        "CSAFPID-5573872",
                        "CSAFPID-5573873",
                        "CSAFPID-5573874",
                        "CSAFPID-5733129",
                        "CSAFPID-5749430",
                        "CSAFPID-712467",
                        "CSAFPID-712470",
                        "CSAFPID-712471",
                        "CSAFPID-712474",
                        "CSAFPID-712482",
                        "CSAFPID-712490",
                        "CSAFPID-712492",
                        "CSAFPID-712493",
                        "CSAFPID-712505",
                        "CSAFPID-712508",
                        "CSAFPID-712509",
                        "CSAFPID-712520",
                        "CSAFPID-814326"
                    ]
                }
            ],
            "title": "CVE-2026-25741"
        }
    ]
}