CVE-2025-61162: Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted req
Summary
Cohere North AI version 1.1.5 has a flaw in its access control (the system that checks whether a user is allowed to perform an action) that lets attackers modify other users' information by sending specially crafted requests to a specific API endpoint. This means an attacker could change someone else's user data without permission.
Vulnerability Details
EPSS: 0.0%
August 26, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-61162
First tracked: August 26, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 92%