Cryptographic Authentication Bypass in OneLogin AD Connector
CVE-2025-34063
Key Information:
- Vendor
One Identity
- Vendor
- CVE Published:
- 1 July 2025
What is CVE-2025-34063?
A vulnerability in the OneLogin AD Connector exposes a tenant’s SSO JWT signing key through the /api/adc/v4/configuration endpoint, allowing attackers to craft valid JWT tokens. This enables them to impersonate any user within a OneLogin tenant, leading to unauthorized access to not only the OneLogin SSO portal but also all downstream applications integrated through SAML or OIDC. The breach poses significant security risks to the affected SaaS environment, as it can facilitate full user impersonation and data exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
OneLogin Active Directory Connector (ADC) 0 < 6.1.5
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
