OIDC Authentication Vulnerability in Looker by Google Cloud
CVE-2025-12414

9.2CRITICAL

Key Information:

Status
Vendor
CVE Published:
20 November 2025

What is CVE-2025-12414?

A vulnerability has been identified in Looker that allows attackers to take over user accounts in environments configured with OIDC authentication. This issue arises from improper email address string normalization, leading to potential security breaches in both Looker-hosted and self-hosted instances. While Looker-hosted environments have received necessary mitigations, self-hosted deployments must be promptly updated to defend against this risk. Users are urged to upgrade to the patched versions to ensure the security of their accounts. For more details and downloads, please visit the Looker download page.

Affected Version(s)

Looker Looker-hosted 0 < 24.12.100

Looker Looker-hosted 0 < 24.18.193

Looker Looker-hosted 0 < 25.0.69

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sivanesh Ashok
Sreeram KL
.
CVE-2025-12414 : OIDC Authentication Vulnerability in Looker by Google Cloud