Home

Description

Control Panel provides an API for pre-registering into an enrollment and organization prior to a user's first login. The API for creating users checks that the account requesting a user creation has `edit` on the enrollment-level user directory, but is missing a separate check that the enrollment editor has access (or belongs to) the organization that they are adding a user to.

PUBLISHED Reserved 2025-10-31 | Published 2025-12-18 | Updated 2025-12-18 | Assigner Palantir




MEDIUM: 4.1CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N

Problem types

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Product status

1.1395.1
unaffected

1.1384.1
unaffected

1.1401.0 (semver) before *
unaffected

* (semver) before 1.1401.0
affected

1.1346.1
unaffected

1.1352.1
unaffected

1.1352.5
unaffected

References

palantir.safebase.us/...52a9fd2f-1868-48cb-af01-93c589160e19

cve.org (CVE-2025-64400)

nvd.nist.gov (CVE-2025-64400)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.