Privilege Escalation Vulnerability in Mendix OIDC SSO Module
CVE-2025-40571

2.1LOW

Key Information:

What is CVE-2025-40571?

A vulnerability exists in the Mendix OIDC SSO module that allows the Administrator role to read and write tokens without proper restrictions. This can lead to misuse by attackers who exploit this weakness to modify the module during Mendix application development. Organizations using affected versions of this module should assess their security posture and take necessary measures to protect against potential unauthorized access.

Affected Version(s)

Mendix OIDC SSO (Mendix 10 compatible) 0

Mendix OIDC SSO (Mendix 9 compatible) 0

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.