OneLogin AD Connector Cryptographic Authentication Bypass Vulnerability Allowing User Impersonation

Vulnerability

A cryptographic authentication bypass vulnerability has been identified in OneLogin AD Connector versions prior to 6.1.5. This vulnerability arises from the exposure of a tenant's SSO JWT signing key through the /api/adc/v4/configuration endpoint. An attacker with access to the signing key can create valid JWT tokens that impersonate users within the OneLogin tenant. These tokens facilitate authentication to the OneLogin SSO portal and all downstream applications federated via SAML or OIDC, granting unauthorized access across the victim's SaaS environment.

Impact

Exploitation of this vulnerability allows for cross-tenant account compromise by impersonating users and accessing their applications within the OneLogin environment.

Reproduction

The vulnerability can be reproduced by sending a request to the OneLogin API configuration endpoint with the directory token and other required parameters. This request will return the SSO IdP configuration, including the signing key. The exposed signing key can then be used to craft JWT tokens that impersonate users in the OneLogin tenant.

Remediation

Users are advised to upgrade to OneLogin AD Connector version 6.1.5 or later.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
7.7
relevance
0.2
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.