Authorization Flaw in Alteryx Server Affects MongoDB Object ID Handling
CVE-2025-63291
What is CVE-2025-63291?
An authorization bypass vulnerability exists in Alteryx Server versions 2022.1.1.42654 and 2024.1 due to inadequate permission checks when processing API requests utilizing MongoDB object IDs. This flaw allows authenticated users to access sensitive data belonging to other users by supplying specific object IDs, potentially exposing critical information such as administrative API keys and private studio API keys. Organizations utilizing these affected versions should assess their API access control mechanisms to mitigate unauthorized data access risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
