Description
Exposure of Private Personal Information to an Unauthorized Actor (CWE-359) in the Command Centre Server allows a privileged Operator to view limited personal data about a Cardholder they would not normally have permissions to view. This issue affects Command Centre Server: 9.30.1874 (MR1), 9.20.2337 (MR3), 9.10.3194 (MR6).
In plain language
AI Low urgencyCVE-2025-35981 is a privacy flaw in Command Centre Server where certain privileged operators may be able to see limited cardholder personal information they normally shouldn’t—most small businesses should treat this as a low-to-medium concern unless you have roles with operator privileges.
CWE-359 private data exposure in Command Centre Server allows a privileged Operator to view limited personal data about a Cardholder outside their intended authorization boundaries (unauthorized authorization to view cardholder details).
What to do now
- Check your Command Centre Server version and see if it is one of: 9.30.1874 (MR1), 9.20.2337 (MR3), or 9.10.3194 (MR6).
- If you are on one of those versions, immediately restrict “Operator” privileges to only the people who truly need them.
- Review and tighten internal permissions around who can view cardholder-related personal data in Command Centre Server.
- Contact your software vendor or support team to ask whether a patch is available for CVE-2025-35981 and request the earliest fixed version for your exact release.
- Increase monitoring of operator activity (especially any viewing of cardholder details) and retain logs for internal review.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
References
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-35981 and every CVE in our database. Create a free account — no credit card required.
Create Free Account