HomeSecurityOneLogin bug allows API Keys to be used to steal OIDC secrets

OneLogin bug allows API Keys to be used to steal OIDC secrets

A serious security vulnerability in One Identity's Identity and Access Management (IAM) solution OneLogincould expose sensitive client secrets of OpenID Connect (OIDC) applications under certain circumstances.

See also: 1Password gets Single Sign-On (SSO) functionality

OneLogin

The vulnerability, tracked as CVE-2025-59363, has a CVSS score of 7.7 out of 10.0. It is described as an instance of improper cross-sphere resource transfer (CWE-669), which causes a program to cross security boundaries and gain unauthorized access to confidential data or functions.

CVE-2025-59363 “ allowed attackers with valid API credentials to enumerate and retrieve client secrets for all OIDC applications within an organization’s OneLogin tenant, ” Clutch Security said in a report shared with The Hacker News.

The issue stems from the fact that the app listing point – /api/2/apps – was configured to return more data than expected, including client_secret values ​​in the API response along with metadata related to the apps in a OneLogin account.

See also: Businesses: Many don't tell customers they are being monitored by third parties

OneLogin bug allows API Keys to be used to steal OIDC secrets

The steps to execute the attack are as follows:

1. The attacker uses valid OneLogin API credentials (client ID and secret) to authenticate.
2. Requests an access token.
3. Calls the /api/2/apps endpoint to list all applications.
4. Parses the response to retrieve client secrets for all OIDC applications.
5. Uses the extracted client secrets to intercept applications and gain access to built-in services.

Successful exploitation of the vulnerability could allow an attacker with valid OneLogin API credentials to retrieve client secrets for all OIDC applications configured within a OneLogin tenant. With this access, the malicious user could leverage the exposed secret to impersonate users and gain access to other applications, providing opportunities for lateral movement.

OneLogin's role-based access control (RBAC) grants API keys broad access to endpoints, meaning compromised credentials could be used to access sensitive endpoints across the platform. Additionally, the lack of an IP whitelist makes it possible to exploit the flaw from anywhere in the world, Clutch noted.

See also: VoidProxy: New phishing service steals credentials

OneLogin bug allows API Keys to be used to steal OIDC secrets

Following a responsible disclosure on July 18, 2025, the vulnerability was addressed in OneLogin 2025.3.0, which was released last month, making OIDC client_secret values ​​invisible. There is no evidence that the issue was ever actively exploited.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS