CVE-2025-27581 is an improper authorization flaw in NIH BRICS (Biomedical Research Informatics Computing System) through version 14.0.0-67. The issue allows users who do not have the required InET role to access the InET module by sending direct requests to known InET endpoints. This indicates that access control for the module is not consistently enforced server-side for those endpoints, permitting role restrictions to be bypassed when a user targets the underlying URLs directly.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains two Bash scripts exploiting CVE-2025-27581, a local privilege escalation vulnerability involving the 'below' utility. The scripts leverage a symlink attack on '/var/log/below/error_root.log' to change permissions on arbitrary files. 'BasicExploit.sh' allows the user to specify any file, attempting to set its permissions to 0666 by exploiting the vulnerability. 'CreateFakeRoot.sh' specifically targets '/etc/passwd', making it world-writable and then appending a new root user entry with a user-supplied password (hashed with SHA-512). This can allow an attacker to gain root access. The exploit requires local access, the ability to run 'below debug dump-store' with sudo, and the ability to manipulate symlinks in the log directory. The repository is structured simply, with two exploit scripts and a README describing their usage and effects.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.