CVE-2025-52925: Onelogin Active Directory Connector

Medium severity, CVSS 5.0. EPSS: 0.2% chance of exploitation in the next 30 days.

In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812.

Affected products

  • Onelogin Active Directory Connector: before 6.1.5 (fixed in 6.1.5)

Published 2025-07-02. Last modified 2026-06-17.