Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-46387

CVE-2025-46387: Authorization Bypass Vulnerability

CVE-2025-46387 is an authorization bypass flaw that exploits user-controlled keys to circumvent access controls. Attackers can gain unauthorized access to restricted resources. This article covers technical details, impact, and mitigation.

Published:

CVE-2025-46387 Overview

CVE-2025-46387 is an authorization bypass vulnerability classified under [CWE-639] Authorization Bypass Through User-Controlled Key. The flaw allows an authenticated attacker to manipulate a user-controlled key parameter to access resources belonging to other users. The vulnerability carries a CVSS 3.1 base score of 8.8, reflecting network exploitability with low attack complexity and low privileges required. Successful exploitation impacts confidentiality, integrity, and availability. The vulnerability was published to the National Vulnerability Database (NVD) on August 6, 2025, and was last updated on April 15, 2026. Affected vendor and product details have not been disclosed in the public advisory at the time of writing.

Critical Impact

An authenticated attacker on the network can bypass authorization checks by manipulating user-controlled identifiers, gaining full read, write, and availability impact over targeted resources.

Affected Products

  • Affected vendor: Not Available in public CVE data
  • Affected product: Not Available in public CVE data
  • Affected versions: Not Available in public CVE data

Discovery Timeline

  • 2025-08-06 - CVE-2025-46387 published to NVD
  • 2026-04-15 - Last updated in NVD database

Technical Details for CVE-2025-46387

Vulnerability Analysis

The vulnerability stems from improper authorization enforcement when an application accepts a key supplied by the user to identify a target resource. The application validates that the user is authenticated, then trusts the user-supplied identifier without verifying that the authenticated principal owns or has rights to the referenced object. An attacker substitutes another user's identifier and the backend returns or modifies data belonging to that user. This pattern is commonly described as an Insecure Direct Object Reference. Because the issue resides in business logic rather than input parsing, common signature-based defenses rarely catch it. The Exploit Prediction Scoring System (EPSS) places this CVE at the 48th percentile, indicating moderate predicted exploitation likelihood.

Root Cause

The root cause is missing or insufficient access-control checks at the object level. The application relies on session authentication but omits a second check confirming that the session user is authorized to act on the requested resource key. Identifiers such as account IDs, order numbers, or document handles are accepted directly from request parameters and passed to data-access routines.

Attack Vector

An attacker authenticates with valid low-privilege credentials, then issues requests over the network in which a user-controlled key (such as userId, accountId, or recordId) is replaced with the identifier of another tenant. No user interaction is required. The vulnerability description in the public CVE record does not include a proof-of-concept. See the Israeli Government CVE Advisories listing for additional context.

Detection Methods for CVE-2025-46387

Indicators of Compromise

  • Authenticated HTTP requests in which the same session token accesses resource identifiers belonging to multiple distinct user accounts within a short window.
  • Sequential or enumerated values in identifier parameters (id=1001, id=1002, id=1003) originating from a single client.
  • Application-layer responses returning 200 OK for resources that historically returned 403 Forbidden for the same principal.

Detection Strategies

  • Instrument application logs to record the authenticated user identifier alongside every accessed resource owner identifier, then alert on mismatches.
  • Deploy runtime application self-protection or API gateway policies that compare session subject claims against resource ownership metadata.
  • Correlate web access logs in a SIEM to detect a single session iterating across object identifiers at machine speed.

Monitoring Recommendations

  • Monitor sudden spikes in unique resource identifiers requested per authenticated session.
  • Track 200/302 response code rates on object-access endpoints by user role and flag deviations.
  • Review authentication, authorization, and audit logs for cross-tenant access patterns on a recurring schedule.

How to Mitigate CVE-2025-46387

Immediate Actions Required

  • Identify any internet-facing application endpoints that accept user-supplied object identifiers and confirm whether the vendor has issued a patch.
  • Apply vendor security updates as soon as they are released and tracked against CVE-2025-46387.
  • Rotate session tokens and audit recent access logs for anomalous cross-account activity.

Patch Information

No vendor patch URL is published in the current CVE record. Administrators should consult the Israeli Government CVE Advisories for vendor identification and patch availability as more information is released by the upstream maintainer.

Workarounds

  • Enforce server-side object-level authorization checks that bind every resource identifier to the authenticated principal before any data is returned.
  • Replace predictable sequential identifiers with unguessable random values such as UUIDv4 to raise the cost of enumeration.
  • Apply API gateway rate limits and anomaly detection to slow automated identifier enumeration attempts.
  • Restrict affected endpoints to trusted networks or VPN access until a vendor fix is deployed.
bash
# Configuration example
# Generic reverse-proxy rule to log and rate-limit object-id enumeration
# (adapt path and parameter name to the affected application)
limit_req_zone $binary_remote_addr zone=objid:10m rate=10r/s;
location /api/resource {
    limit_req zone=objid burst=5 nodelay;
    access_log /var/log/nginx/objid_access.log;
    proxy_pass http://backend;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.