OneLogin Bug Let Attackers Use API Keys to Steal OIDC Secrets and Impersonate Apps
One Identity OneLogin Identity and Access Management (IAM) has been found to have a high-severity security weakness that, in some cases, could reveal private OpenID Connect (OIDC) application client secrets if it is successfully exploited.
The vulnerability has a CVSS score of 7.7 out of 10.0 and is tagged as CVE-2025-59363. According to CWE-669, it is an instance of improper resource transfer between spheres that allows a program to breach security perimeters and get unauthorized access to private information or features.
According to a report sent to The Hacker News by Clutch Security, CVE-2025-59363 enabled attackers with legitimate API credentials to list and obtain client secrets for any OIDC application running in a company's OneLogin tenant.
The application listing endpoin...

