

An issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to various API endpoints.
Published:
12 January 2026 at 23:00:00
Alert date:
13 January 2026 at 18:02:00
Source:
nvd.nist.gov
Web Technologies, Identity & Access
A security vulnerability in Semantic machines version 5.4.8 allows attackers to bypass authentication mechanisms by sending specially crafted HTTP requests to various API endpoints. This authentication bypass vulnerability could allow unauthorized access to protected resources and API functionality. The vulnerability has been assigned CVE-2025-66698 and affects the specific version 5.4.8 of the Semantic machines software. Proof of concept code appears to be available on GitHub, indicating potential for exploitation.
Technical details
Mitigation steps:
Affected products:
Semantic machines
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-66698
http://semantic.com
http://veda.com
https://github.com/Perunchess/CVE-2025-66698
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.

