PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-60949 Census CVE debrief

CVE-2025-60949 is a critical vulnerability in Census CSWeb 8.0.1 that allows remote, unauthenticated attackers to access configuration files via HTTP in certain deployments. This could lead to the leakage of sensitive information. The issue has been addressed in version 8.1.0 alpha. Users of affected versions should update as soon as possible. The vulnerability has a CVSS score of 9.1, indicating a high severity. The CVE was published on February 23, 2026.

Vendor
Census
Product
CSWeb
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-02-23
Original CVE updated
2026-02-23
Advisory published
2026-02-23
Advisory updated
2026-02-23

Who should care

System administrators and security teams using Census CSWeb, especially those with deployments that may expose 'app/config' via HTTP, should be aware of this vulnerability. Immediate action is recommended to prevent potential exploitation. Updating to version 8.1.0 alpha or later is crucial.

Technical summary

The vulnerability in Census CSWeb 8.0.1 arises from the accessibility of 'app/config' via HTTP in some deployments. An unauthenticated remote attacker can exploit this by sending requests to configuration files, potentially obtaining leaked secrets. The issue is resolved in version 8.1.0 alpha. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, reflecting a high impact on confidentiality and integrity.

Defensive priority

High priority should be given to updating Census CSWeb to version 8.1.0 alpha or later. In the meantime, restricting access to 'app/config' and monitoring for suspicious activity are recommended defensive measures.

Recommended defensive actions

  • Update Census CSWeb to version 8.1.0 alpha or later immediately.
  • Restrict access to 'app/config' via HTTP in deployments where feasible.
  • Monitor for suspicious requests to configuration files.
  • Review and adjust network configurations to prevent exposure of 'app/config'.
  • Consider compensating controls such as web application firewalls.

Evidence notes

The source item provided by CISA (cisa_csaf) details the vulnerability and its fix. Additional references include the CVE record and NVD detail pages. The information indicates a high severity vulnerability that requires prompt action.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-60949 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-60949

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-60949 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-60949

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-082-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://github.com/hx381/cspro-exploits

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://github.com/csprousers/csweb/commit/eba0b59a243390a1a4f9524cce6dbc0314bf0d91

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.