CVE-2025-57817

HIGH

Fides < 2.69.1 - Missing Authorization in OAuth Client Scope Assignment

Title source: llm
STIX 2.1

Description

Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the OAuth client creation and update endpoints of the Fides Webserver API do not properly authorize scope assignment. This allows highly privileged users with `client:create` or `client:update` permissions to escalate their privileges to owner-level. Version 2.69.1 fixes the issue. No known workarounds are available.

Scores

CVSS v3 7.2
EPSS 0.0010
EPSS Percentile 26.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-862
Status published
Products (2)
ethyca/fides < 2.69.1
pypi/ethyca-fides 0 - 2.69.1PyPI
Published Sep 08, 2025
Tracked Since Feb 18, 2026