Ethical Hacking News
A high-severity vulnerability in OneLogin has left sensitive OpenID Connect application client secrets exposed, posing a significant risk to users' identities and data. Learn more about this critical cybersecurity threat and the steps being taken to address it.
The OneLogin Identity and Access Management (IAM) solution has a high-severity vulnerability (CVE-2025-59363) that poses an unprecedented risk to sensitive OpenID Connect application client secrets. The flaw is due to a critical misconfiguration in the application listing endpoint, which returns more data than expected, including client_secret values. Attackers can exploit this vulnerability by using valid OneLogin API credentials to enumerate and retrieve client secrets for all OIDC applications within an organization's tenant. The implications of this vulnerability are far-reaching, allowing attackers to gain unauthorized access to other applications and potentially leverage compromised credentials to access sensitive endpoints across the platform. The lack of IP address allowlisting makes it possible for attackers to exploit the flaw from anywhere in the world without physical access or proximity. The vulnerability was addressed in OneLogin 2025.3.0, which makes OIDC client_secret values no longer visible.
The cybersecurity landscape has been abuzz with the revelation of a high-severity vulnerability in the One Identity OneLogin Identity and Access Management (IAM) solution, leaving experts and organizations on high alert. The newly discovered flaw, tracked as CVE-2025-59363, poses an unprecedented risk to sensitive OpenID Connect application client secrets within OneLogin tenants, potentially exposing users to identity theft, unauthorized access, and other malicious activities.
The vulnerability stems from a critical misconfiguration in the application listing endpoint – /api/2/apps – which inadvertently returns more data than expected, including the client_secret values alongside metadata related to the applications. This oversight allows attackers with valid OneLogin API credentials to enumerate and retrieve client secrets for all OIDC applications within an organization's OneLogin tenant.
According to Clutch Security, a leading cybersecurity firm that first disclosed the vulnerability on July 18, 2025, attackers can exploit this flaw by using valid OneLogin API credentials (client ID and secret) to authenticate, request access tokens, call the /api/2/apps endpoint to list all applications, parse the response to retrieve client secrets for all OIDC applications, and finally use extracted client secrets to impersonate applications and access integrated services.
The implications of this vulnerability are far-reaching. With sensitive OpenID Connect application client secrets exposed, attackers can potentially leverage them to gain unauthorized access to other applications, offering opportunities for lateral movement within the organization. Furthermore, OneLogin's role-based access control (RBAC) grants API keys broad endpoint access, making it possible for compromised credentials to be used to access sensitive endpoints across the entire platform.
Compounding matters further is the lack of IP address allowlisting, which allows attackers to exploit the flaw from anywhere in the world. This makes the OneLogin vulnerability particularly concerning, as it can be exploited remotely without the need for physical access or proximity.
Fortunately, Clutch Security reports that the vulnerability was addressed in OneLogin 2025.3.0, released last month, by making OIDC client_secret values no longer visible. While there is currently no evidence that the issue was ever exploited in the wild, this finding serves as a stark reminder of the importance of rigorous API security measures.
The disclosure of this vulnerability highlights the need for organizations to prioritize robust cybersecurity practices and ensure that their identity management solutions are equipped with adequate security features to prevent similar incidents. As identity providers serve as the backbone of enterprise security architecture, vulnerabilities in these systems can have cascading effects across entire technology stacks, making it essential to maintain vigilance and proactive measures against such threats.
In conclusion, the OneLogin vulnerability serves as a wake-up call for organizations to reassess their cybersecurity posture and implement necessary safeguards to prevent similar breaches. As the threat landscape continues to evolve, it is crucial for businesses and organizations to stay informed and adapt their security strategies to mitigate potential risks.
Related Information:
https://www.ethicalhackingnews.com/articles/The-Looming-Threat-of-OneLogin-Vulnerability-A-Cybersecurity-Nightmare-Unfolding-ehn.shtml
https://thehackernews.com/2025/10/onelogin-bug-let-attackers-use-api-keys.html
https://nvd.nist.gov/vuln/detail/CVE-2025-59363
https://www.cvedetails.com/cve/CVE-2025-59363/
Published: Wed Oct 1 09:43:45 2025 by llama3.2 3B Q4_K_M