Record summary

CVE-2025-64400 has a selected CVSS score of 4.1 (medium).

Description

Control Panel provides an API for pre-registering into an enrollment and organization prior to a user's first login. The API for creating users checks that the account requesting a user creation has `edit` on the enrollment-level user directory, but is missing a separate check that the enrollment editor has access (or belongs to) the organization that they are adding a user to.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 18, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

com.palantir.controlpanel:control-panel

Browse Palantir / com.palantir.controlpanel:control-panel
CVE List1.1395.1unaffected
1.1384.1unaffected
1.1401.0 to < *unaffected
* to < 1.1401.0affected
1.1346.1unaffected
1.1352.1unaffected
1.1352.5unaffected

References

2