Authorization Flaw in Alteryx Server Affects MongoDB Object ID Handling
CVE-2025-63291

5.4MEDIUM

Key Information:

Vendor

Alteryx

Vendor
CVE Published:
14 November 2025

What is CVE-2025-63291?

An authorization bypass vulnerability exists in Alteryx Server versions 2022.1.1.42654 and 2024.1 due to inadequate permission checks when processing API requests utilizing MongoDB object IDs. This flaw allows authenticated users to access sensitive data belonging to other users by supplying specific object IDs, potentially exposing critical information such as administrative API keys and private studio API keys. Organizations utilizing these affected versions should assess their API access control mechanisms to mitigate unauthorized data access risks.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-63291 : Authorization Flaw in Alteryx Server Affects MongoDB Object ID Handling