CVE-2025-40571

A vulnerability has been identified in Mendix OIDC SSO (Mendix 10 compatible) (All versions < V4.1.0), Mendix OIDC SSO (Mendix 10.12 compatible) (All versions < V4.0.1), Mendix OIDC SSO (Mendix 9 compatible) (All versions). The Mendix OIDC SSO module grants read and write access to all tokens exclusively to the Administrator role and could result in privilege misuse by an adversary modifying the module during Mendix development.
Configurations

No configuration.

History

12 Jun 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-13 10:15

Updated : 2025-06-12 08:15


NVD link : CVE-2025-40571

Mitre link : CVE-2025-40571

CVE.ORG link : CVE-2025-40571


JSON object : View

Products Affected

No product.

CWE
CWE-266

Incorrect Privilege Assignment