API Misconfiguration in Control Panel Affects Enrollment Systems by Palantir
CVE-2025-64400
What is CVE-2025-64400?
The Control Panel's user creation API allows pre-registration into an enrollment and organization before a user's initial login. While this API checks that the requestor has edit permissions on the enrollment-level user directory, it fails to validate that the enrollment editor is properly associated with the organization for which they are adding a user. This oversight can lead to unauthorized access and manipulation of user accounts in the system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
com.palantir.controlpanel:control-panel * < 1.1401.0
com.palantir.controlpanel:control-panel 1.1395.1
com.palantir.controlpanel:control-panel 1.1384.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
