CVE-2025-58137 Details
Description
Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1. Users are encouraged to upgrade to version 1.13.0, the latest release.
An authorization bypass vulnerability allowing insecure direct object references (IDOR) has been identified in Apache Fineract versions prior to 1.11.0. This vulnerability arises from user-controlled keys that can bypass authorization checks, potentially leading to unauthorized access or manipulation of resources through the self-service API.
Users are advised to upgrade to Apache Fineract version 1.12.1 or later. The latest release is version 1.13.0.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/12/11/7 | CVE | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/gz3zhoghlclch3rdnzyrdcf69c0507ww | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache fineract | < 1.12.1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 18, 2025 | Initial Analysis | [email protected] |
| Dec 12, 2025 | CVE Modified | CISA-ADP |
| Dec 12, 2025 | New CVE Received | [email protected] |
| Dec 12, 2025 | CVE Modified | CVE |