nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-64400 CVE-2025-64400
MEDIUM
Insufficient permission checks when pre-enrolling users Summary
Record summary
CVE-2025-64400 has a selected CVSS score of 4.1 (medium).
Description
Control Panel provides an API for pre-registering into an enrollment and organization prior to a user's first login. The API for creating users checks that the account requesting a user creation has `edit` on the enrollment-level user directory, but is missing a separate check that the enrollment editor has access (or belongs to) the organization that they are adding a user to.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 18, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
com.palantir.controlpanel:control-panelBrowse Palantir / com.palantir.controlpanel:control-panel | CVE List | 1.1395.1 | unaffected |
| 1.1384.1 | unaffected | ||
| 1.1401.0 to < * | unaffected | ||
| * to < 1.1401.0 | affected | ||
| 1.1346.1 | unaffected | ||
| 1.1352.1 | unaffected | ||
| 1.1352.5 | unaffected |
References
2palantir.safebase.us
https://palantir.safebase.us/?tcuUid=52a9fd2f-1868-48cb-af01-93c589160e19