CVE-2025-52925: Onelogin Active Directory Connector
Medium severity, CVSS 5.0. EPSS: 0.2% chance of exploitation in the next 30 days.
In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812.
Affected products
- Onelogin Active Directory Connector: before 6.1.5 (fixed in 6.1.5)
Published 2025-07-02. Last modified 2026-06-17.