CVE-2025-63291 Details
Description
When processing API requests, the Alteryx server 2022.1.1.42654 and 2024.1 used MongoDB object IDs to uniquely identify the data being requested by the caller. The Alteryx server did not check whether the authenticated user had permission to access the specified MongoDB object ID. By specifying particlar MongoDB object IDs, callers could obtain records for other users without proper authorization. Records retrievable using this attack included administrative API keys and private studio api keys.
A vulnerability exists in Alteryx Server versions 2022.1.1.42654 and 2024.1 that allows authenticated users to bypass authorization checks and access data belonging to other users. This issue arises from the server's use of MongoDB object IDs to identify requested data without verifying whether the user has permission to access it. By manipulating these object IDs, attackers can retrieve sensitive information such as administrative and private studio API keys from the targeted users' profiles.
Users are advised to update to Alteryx Server and Client versions 2024.1 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
| CWE-648 | Incorrect Use of Privileged APIs | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| alteryx alteryx server | >= 2022.1.0, <= 2022.1.1.42654 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | Reanalysis | [email protected] |
| Jan 12, 2026 | Initial Analysis | [email protected] |
| Nov 16, 2025 | CVE Modified | CISA-ADP |
| Nov 14, 2025 | CVE Modified | CISA-ADP |
| Nov 14, 2025 | New CVE Received | [email protected] |