Cyber Posture

CVE-2025-10226

Critical

Published: 10 September 2025

Published
10 September 2025
Modified
19 December 2025
KEV Added
Patch
CVSS Score 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0064 70.6th percentile
Risk Priority 20 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2025-10226 is a critical-severity an unspecified weakness vulnerability in Axxonsoft Axxon One. Its CVSS base score is 9.8 (Critical).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked in the top 29.4% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 RA-5 (Vulnerability Monitoring and Scanning) and SA-22 (Unsupported System Components).

Threat & Defense at a Glance

What attackers do: exploitation maps to Exploit Public-Facing Application (T1190) and 1 other technique. What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

Directly requires timely remediation of known flaws in third-party components like the multiple CVEs in PostgreSQL v10.x used by Axxon One.

detect

Mandates vulnerability scanning to identify and prioritize the outdated PostgreSQL v10.x components containing exploitable CVEs.

prevent

Prohibits use of unsupported system components such as PostgreSQL v10.x, which harbors unresolved vulnerabilities enabling remote exploitation.

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
T1068 Exploitation for Privilege Escalation Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Why these techniques?

The CVE describes unauthenticated remote exploitation of a public-facing PostgreSQL backend component (CWE-1395) leading directly to RCE and privilege escalation, mapping to T1190 for the initial network exploitation vector and T1068 for the resulting escalation.

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

NVD Description

Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier on Windows and Linux allows a remote attacker to escalate privileges, execute arbitrary code, or cause denial-of-service via exploitation of multiple known…

more

CVEs present in PostgreSQL v10.x, which are resolved in PostgreSQL 17.4.

Deeper analysisAI

CVE-2025-10226 is a Dependency on Vulnerable Third-Party Component vulnerability (CWE-1395) in the PostgreSQL backend of AxxonSoft Axxon One (C-Werk) version 2.0.8 and earlier, affecting deployments on both Windows and Linux. The flaw arises from reliance on PostgreSQL v10.x, which includes multiple known CVEs that enable exploitation. These underlying issues have been resolved in PostgreSQL 17.4. The vulnerability carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), marking it as critical.

A remote attacker requires no privileges, user interaction, or special access and can exploit the vulnerability over the network with low attack complexity. Successful exploitation allows privilege escalation, arbitrary code execution, or denial-of-service against the affected Axxon One instance.

For mitigation guidance, refer to AxxonSoft's security advisories at https://www.axxonsoft.com/legal/axxonsoft-vulnerability-disclosure-policy/security-advisories and PostgreSQL release documentation at https://www.postgresql.org/docs/release, which detail patches and upgrades addressing the vulnerable PostgreSQL v10.x components.

Details

CWE(s)

Affected Products

axxonsoft
axxon one
≤ 2.0.8

CVEs Like This One

CVE-2025-69274Same product: Linux Linux Kernel
CVE-2025-23318Same product: Linux Linux Kernel
CVE-2025-23310Same product: Linux Linux Kernel
CVE-2025-69273Same product: Linux Linux Kernel
CVE-2025-23317Same product: Linux Linux Kernel
CVE-2025-23311Same product: Linux Linux Kernel
CVE-2026-28710Same product: Linux Linux Kernel
CVE-2024-51954Same product: Linux Linux Kernel
CVE-2025-23319Same product: Linux Linux Kernel
CVE-2026-31705Same product: Linux Linux Kernel

References