Tag: OneLogin Bug

OneLogin Bug Let Attackers Use API Keys to Steal OIDC Secrets and Impersonate Apps
News

OneLogin Bug Let Attackers Use API Keys to Steal OIDC Secrets and Impersonate Apps

One Identity OneLogin Identity and Access Management (IAM) has been found to have a high-severity security weakness that, in some cases, could reveal private OpenID Connect (OIDC) application client secrets if it is successfully exploited. The vulnerability has a CVSS score of 7.7 out of 10.0 and is tagged as CVE-2025-59363. According to CWE-669, it is an instance of improper resource transfer between spheres that allows a program to breach security perimeters and get unauthorized access to private information or features. According to a report sent to The Hacker News by Clutch Security, CVE-2025-59363 enabled attackers with legitimate API credentials to list and obtain client secrets for any OIDC application running in a company's OneLogin tenant. The application listing endpoin...