A cryptographic authentication bypass vulnerability exists in OneLogin AD Connector prior to 6.1.5 due to the exposure of a tenant’s SSO JWT signing key via the /api/adc/v4/configuration endpoint. An attacker in possession of the signing key can craft valid JWT tokens impersonating arbitrary users within a OneLogin tenant. The tokens allow authentication to the OneLogin SSO portal and all downstream applications federated via SAML or OIDC. This allows full unauthorized access across the victim’s SaaS environment.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Jul 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 01 Jul 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A cryptographic authentication bypass vulnerability exists in OneLogin AD Connector prior to 6.1.5 due to the exposure of a tenant’s SSO JWT signing key via the /api/adc/v4/configuration endpoint. An attacker in possession of the signing key can craft valid JWT tokens impersonating arbitrary users within a OneLogin tenant. The tokens allow authentication to the OneLogin SSO portal and all downstream applications federated via SAML or OIDC. This allows full unauthorized access across the victim’s SaaS environment. | |
Title | OneLogin AD Connector JWT Authentication Bypass via Exposed Signing Key | |
Weaknesses | CWE-290 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-07-01T14:49:25.544Z
Updated: 2025-07-01T15:17:11.538Z
Reserved: 2025-04-15T19:15:22.549Z
Link: CVE-2025-34063

Updated: 2025-07-01T15:16:56.630Z

Status : Awaiting Analysis
Published: 2025-07-01T15:15:24.913
Modified: 2025-07-03T15:14:12.767
Link: CVE-2025-34063

No data.