Security Advisory

CVE-2025-34063

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-07-01 14:49:25
Last updated 2025-07-01 15:17:11
Assigner VulnCheck
CVSS score not scored
State PUBLISHED

Description

A cryptographic authentication bypass vulnerability exists in OneLogin AD Connector prior to 6.1.5 due to the exposure of a tenant’s SSO JWT signing key via the /api/adc/v4/configuration endpoint. An attacker in possession of the signing key can craft valid JWT tokens impersonating arbitrary users within a OneLogin tenant. The tokens allow authentication to the OneLogin SSO portal and all downstream applications federated via SAML or OIDC. This allows full unauthorized access across the victim’s SaaS environment.