CVE-2025-64400
BaseFortify
Publication date: 2025-12-18
Last updated on: 2025-12-19
Assigner: Palantir Technologies
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the Control Panel's API for pre-registering users into an enrollment and organization before their first login. The API verifies that the account creating a user has 'edit' permissions on the enrollment-level user directory but fails to check whether the enrollment editor actually has access to or belongs to the organization they are adding the user to. This missing check could allow unauthorized user creation within organizations.
How can this vulnerability impact me? :
This vulnerability could allow an attacker or unauthorized user with enrollment-level edit permissions to add users to organizations they do not belong to or have access to. This may lead to unauthorized access or manipulation of organizational user data, potentially compromising organizational security boundaries.