Privilege Escalation in Fides Webserver API Affects Open-Source Privacy Engineering Platform
CVE-2025-57817
What is CVE-2025-57817?
The Fides Webserver API, a privacy engineering platform by Ethyca, contains a vulnerability that allows users with elevated privileges, specifically those granted client:create or client:update, to bypass authorization controls related to scope assignment. This flaw can lead to unauthorized escalation of permissions to owner-level within the platform. The issue was resolved in version 2.69.1 of Fides, and updates are highly recommended as there are currently no known workarounds for this vulnerability. For further details, refer to the official advisory and release notes.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
fides < 2.69.1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
