CVE-2025-59363: One Identity Onelogin

High severity, CVSS 7.7. EPSS: 0.3% chance of exploitation in the next 30 days.

In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though this secret should only be returned when an App is first created),

Affected products

Published 2025-09-14. Last modified 2026-06-17.