CVE-2025-63291

MEDIUM

Alteryx Server 2022.1.1.42654-2024.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

When processing API requests, the Alteryx server 2022.1.1.42654 and 2024.1 used MongoDB object IDs to uniquely identify the data being requested by the caller. The Alteryx server did not check whether the authenticated user had permission to access the specified MongoDB object ID. By specifying particlar MongoDB object IDs, callers could obtain records for other users without proper authorization. Records retrievable using this attack included administrative API keys and private studio api keys.

Scores

CVSS v3 5.4
EPSS 0.0004
EPSS Percentile 12.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-639 CWE-648
Status published
Products (1)
alteryx/alteryx_server 2022.1.0 - 2022.1.1.42654
Published Nov 14, 2025
Tracked Since Feb 18, 2026