Summary & Key Actions Required
Avantra has identified a security issue in the password-change functionality where an authenticated user could repeatedly attempt to modify another user's credentials.
This issue affects Avantra Server versions 25.2 and above.
This issue is fixed in Avantra Server versions 26.6.9 and 25.3.8.
Mitigation
We have completed our investigation into this issue and released patches for customers to apply immediately.
The affected operation is now restricted to the authenticated user's own account, and repeated attempts are rate-limited.
Customers running Avantra 26 are advised to upgrade to at least version 26.6.9. Customers running Avantra 25.3 are advised to upgrade to at least version 25.3.8.
We, at Avantra, take the security of our software and our customers very seriously and it is our top priority. We will keep you up to date as more information becomes available and encourage customers to subscribe to the security section of our forum to get proactive updates as we post them.