Privilege Escalation Vulnerability in Mendix OIDC SSO Module
CVE-2025-40571
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 13 May 2025
What is CVE-2025-40571?
A vulnerability exists in the Mendix OIDC SSO module that allows the Administrator role to read and write tokens without proper restrictions. This can lead to misuse by attackers who exploit this weakness to modify the module during Mendix application development. Organizations using affected versions of this module should assess their security posture and take necessary measures to protect against potential unauthorized access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mendix OIDC SSO (Mendix 10 compatible) 0
Mendix OIDC SSO (Mendix 10.12 compatible) 0
Mendix OIDC SSO (Mendix 9 compatible) 0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved