PatchSiren cyber security CVE debrief
CVE-2025-60946 Census CVE debrief
CVE-2025-60946 is a high-severity path traversal vulnerability in Census CSWeb 8.0.1. An authenticated attacker could access unintended file directories. The issue was fixed in version 8.1.0 alpha. According to the CVE record, the vulnerability has a CVSS score of 8.8, indicating a high severity level. The source item from CISA CSAF provides detailed information about the vulnerability, including its description, affected products, and remediation steps.
- Vendor
- Census
- Product
- CSWeb
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-23
- Original CVE updated
- 2026-02-23
- Advisory published
- 2026-02-23
- Advisory updated
- 2026-02-23
Who should care
Organizations using Census CSWeb 8.0.1 should prioritize patching to prevent potential exploitation. Security teams and administrators responsible for maintaining Census CSWeb installations should be aware of this vulnerability and take immediate action to mitigate the risk. Additionally, developers and security researchers interested in understanding the vulnerability and its implications may also find this information valuable.
Technical summary
CVE-2025-60946 is a path traversal vulnerability in Census CSWeb 8.0.1, allowing an authenticated attacker to access unintended file directories. The vulnerability is caused by arbitrary file path input. The issue was fixed in version 8.1.0 alpha. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating a high severity level. The source item from CISA CSAF provides detailed information about the vulnerability, including its description, affected products, and remediation steps.
Defensive priority
High priority should be given to patching Census CSWeb installations to prevent potential exploitation. Security teams should verify that their installations are updated to version 8.1.0 alpha or later.
Recommended defensive actions
- Patch Census CSWeb installations to version 8.1.0 alpha or later.
- Verify that Census CSWeb installations are updated to version 8.1.0 alpha or later.
- Monitor Census CSWeb installations for potential exploitation attempts.
- Review and update security policies and procedures to ensure that Census CSWeb installations are properly secured.
- Conduct a thorough risk assessment to identify potential vulnerabilities and prioritize remediation efforts.
Evidence notes
The source item from CISA CSAF provides detailed information about the vulnerability, including its description, affected products, and remediation steps. The CVE record and NVD detail provide additional information about the vulnerability, including its CVSS score and vector. The source references provide additional context and information about the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-60946 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-60946
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-60946 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-60946
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-082-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://github.com/csprousers/csweb/commit/eba0b59a243390a1a4f9524cce6dbc0314bf0d91
Reference
-
Source reference
Unverified legacy reference
URL: https://github.com/hx381/cspro-exploits
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.