CVE-2025-34063

CRITICAL

OneLogin AD Connector <6.1.5 - Auth Bypass

Title source: llm
STIX 2.1

Description

A cryptographic authentication bypass vulnerability exists in OneLogin AD Connector prior to 6.1.5 due to the exposure of a tenant’s SSO JWT signing key via the /api/adc/v4/configuration endpoint. An attacker in possession of the signing key can craft valid JWT tokens impersonating arbitrary users within a OneLogin tenant. The tokens allow authentication to the OneLogin SSO portal and all downstream applications federated via SAML or OIDC. This allows full unauthorized access across the victim’s SaaS environment.

Scores

CVSS v4 10.0
EPSS 0.0036
EPSS Percentile 58.2%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-290
Status published
Products (1)
One Identity/OneLogin Active Directory Connector (ADC) < 6.1.5
Published Jul 01, 2025
Tracked Since Feb 18, 2026