#VU120247 Authorization bypass through user-controlled key in Fineract - CVE-2025-58137
Published: December 23, 2025
Fineract
Apache Foundation
Description
The vulnerability allows a remote user to bypass authorization checks.
The vulnerability exists due to the application does not perform authorization checks within the self-service API endpoint when allowing users to manipulate with application identifiers. A remote user can bypass implemented security restrictions by manipulating parameters in the requests.