CVE-2025-59363: One Identity Onelogin
High severity, CVSS 7.7. EPSS: 0.3% chance of exploitation in the next 30 days.
In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though this secret should only be returned when an App is first created),
Affected products
- One Identity Onelogin: before 2025.3.0 (fixed in 2025.3.0)
Published 2025-09-14. Last modified 2026-06-17.