CVE-2025-66223 Details
Description
OpenObserve is a cloud-native observability platform. Prior to version 0.16.0, organization invitation tokens do not expire once issued, remain valid even after the invited user is removed from the organization, and allow multiple invitations to the same email with different roles where all issued links remain valid simultaneously. This results in broken access control where a removed or demoted user can regain access or escalate privileges. This issue has been patched in version 0.16.0.
A vulnerability exists in OpenObserve versions prior to 0.16.0, where organization invitation tokens do not expire, remain valid after a user is removed, and allow multiple simultaneous invitations to the same email with different roles. This mismanagement of invitation tokens creates a broken access control scenario, enabling removed or demoted users to regain access or escalate privileges.
Users are advised to update to OpenObserve version 0.16.0 or later. Invitation tokens should be configured to expire after use, invalidate previous tokens when a new invite is issued, and be revoked when a user is removed from an organization.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 29, 2025CISA-ADP
Assessed Dec 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/openobserve/openobserve/security/advisories/GHSA-c856-2xpx-gw75 | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
| CWE-613 | Insufficient Session Expiration | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OpenObserve | < 0.16.0 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 29, 2025 | New CVE Received | [email protected] |
Volerion