CVE-2025-56449 Details
Description
A security vulnerability was identified in Obsidian Scheduler's REST API 5.0.0 thru 6.3.0. If an account is locked out due to not enrolling in MFA (e.g. after the 7-day enforcement window), the REST API still allows the use of Basic Authentication to authenticate and perform administrative actions. In particular, the default admin account was found to be locked out via the web interface but still usable through the REST API. This allowed creation of a new privileged user, bypassing MFA protections. This undermines the intended security posture of MFA enforcement.
A vulnerability exists in Obsidian Scheduler's REST API versions 5.0.0 through 6.3.0, allowing accounts locked out for not enrolling in multi-factor authentication (MFA) to authenticate using Basic Authentication and perform administrative actions. This issue arises from inconsistent authentication enforcement, enabling access to locked accounts via the REST API while the web interface denies it. Exploiting this flaw can lead to unauthorized administrative access and the creation of privileged users, bypassing MFA protections.
Users are advised to update Obsidian Scheduler to version 6.3.1. If an immediate upgrade is not possible, consider running Obsidian Scheduler as a standalone or embedded service, disabling REST endpoints via the 'web.xml' configuration file, or invalidating passwords for users without MFA enabled.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2025CISA-ADP
Assessed Sep 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://blog.gregscharf.com/2025/07/11/upcoming-vulnerability-advisory/ | [email protected] | AdvisoryPartial Content |
| https://blog.gregscharf.com/2025/07/31/obsidian-scheduler-access-control-vulnerability/ | [email protected] | ExploitRemedyTechnical Analysis |
| https://wiki.obsidianscheduler.com/docs/Release_Notes#Obsidian_6.3.1 | [email protected] | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Obsidian Scheduler | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 28, 2025 | CVE Modified | CISA-ADP |
| Sep 29, 2025 | New CVE Received | [email protected] |
Volerion