Executive Summary
In October 2025, a critical security vulnerability (CVE-2025-59363, CVSS 7.7) was disclosed in the One Identity OneLogin IAM platform. The flaw allowed threat actors to use compromised or exposed API keys to retrieve sensitive OpenID Connect (OIDC) application client secrets. Attackers exploiting this vulnerability could potentially impersonate trusted applications, resulting in unauthorized access to protected enterprise resources and disruption of identity-based authentication flows. OneLogin responded with a patch following public disclosure, but the exposure window placed numerous organizations at risk of credential theft and downstream compromise.
This incident highlights persistent risks in identity and access management platforms, especially around API security and secret handling. Recent trends show attackers increasingly targeting IAM tools and exploiting weak OIDC/OAuth implementations, making robust zero trust segmentation, continuous threat monitoring, and compliance with established frameworks more critical than ever.
Why This Matters Now
With API-driven identity platforms forming the backbone of secure enterprise access, flaws in OIDC secret management now constitute a significant attack surface. The rapid growth of SaaS and cloud adoption makes such vulnerabilities urgent, as they can result in widespread privilege escalation, regulatory risk, and loss of trust if not swiftly addressed.
Attack Path Analysis
The attacker exploited a vulnerability in OneLogin to obtain unauthorized access via exposed or misused API keys. With these keys, the attacker leveraged misconfigurations or weaknesses in IAM controls to escalate privileges and extract sensitive OIDC client secrets. Using the compromised credentials and secrets, the attacker laterally moved within the cloud environment to locate additional targets. Command and Control was established as the attacker maintained persistence and issued commands to expand access or prepare data exfiltration. Sensitive OIDC secrets and possibly other assets were exfiltrated out of the environment. The impact included impersonation of applications, potential unauthorized authentication, and data exposure.
Kill Chain Progression
Initial Compromise
Description
Attacker exploited CVE-2025-59363 by leveraging exposed or misused API keys in OneLogin to gain unauthorized initial access to the IAM environment.
Related CVEs
CVE-2025-59363
CVSS 7.7In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though this secret should only be returned when an App is first created).
Affected Products:
One Identity OneLogin – < 2025.3.0
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Unsecured Credentials
Valid Accounts
Data from Cloud Storage Object
Credentials from Password Stores
Active Scanning
Exploitation of Remote Services
Account Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Secure Authentication and Identification
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Security Testing and Vulnerability Management
Control ID: Art. 9(1)
CISA ZTMM 2.0 – Secure Identity Credentials and Secrets
Control ID: Identity Pillar - Secure Identity Stores
NIS2 Directive – Technical and Organizational Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
OneLogin IAM vulnerability exposing OIDC secrets creates critical identity compromise risks for banking systems, potentially enabling unauthorized access to financial applications and customer data.
Health Care / Life Sciences
High-severity IAM flaw threatens patient data protection through compromised application authentication, violating HIPAA compliance requirements and enabling unauthorized access to medical systems.
Government Administration
Identity management vulnerability in OneLogin poses significant risks to government digital services, potentially compromising citizen data access and critical infrastructure authentication mechanisms.
Information Technology/IT
CVE-2025-59363 directly impacts IT organizations using OneLogin for identity management, creating application impersonation risks and compromising zero trust security architectures.
Sources
- OneLogin Bug Let Attackers Use API Keys to Steal OIDC Secrets and Impersonate Appshttps://thehackernews.com/2025/10/onelogin-bug-let-attackers-use-api-keys.htmlVerified
- NVD - CVE-2025-59363https://nvd.nist.gov/vuln/detail/CVE-2025-59363Verified
- OneLogin Product Notificationhttps://onelogin.service-now.com/support?id=kb_article&sys_id=b0aad1e11bd3ea109a47ec29b04bcb72&kb_category=a0d76d70db185340d5505eea4b96199fVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, egress policy enforcement, centralized visibility, and inline threat detection would have significantly disrupted the attacker's ability to exploit the IAM vulnerability, move laterally, and exfiltrate OIDC secrets. Applying workload-to-workload segmentation and tight egress controls aligned with CNSF capabilities would have minimized exposure and enabled rapid detection of anomalous access or data movement.
Control: Zero Trust Segmentation
Mitigation: Minimized attack surface and limited unauthorized API access.
Control: Multicloud Visibility & Control
Mitigation: Enabled centralized monitoring of privilege misuse and policy deviations.
Control: East-West Traffic Security
Mitigation: Restricted unauthorized lateral movement within the network.
Control: Threat Detection & Anomaly Response
Mitigation: Rapid detection of anomalous remote access or covert C2 communications.
Control: Egress Security & Policy Enforcement
Mitigation: Blocked or detected unauthorized outbound data transfers.
Contained post-compromise blast radius, reducing scope for impersonation.
Impact at a Glance
Affected Business Functions
- Identity and Access Management
Estimated downtime: 2 days
Estimated loss: $50,000
Potential exposure of OIDC client secrets could allow attackers to impersonate applications, leading to unauthorized access to sensitive data and services.
Recommended Actions
Key Takeaways & Next Steps
- • Implement strict Zero Trust Segmentation on all IAM-related APIs and workloads to prevent unauthorized key usage.
- • Enforce real-time egress filtering and granular outbound controls for sensitive cloud environments to block exfiltration of secrets.
- • Leverage centralized multicloud visibility and automated anomaly detection to promptly identify suspicious access or privilege escalation.
- • Apply microsegmentation and east-west network traffic controls to restrict lateral movement via compromised service credentials.
- • Regularly audit and rotate application secrets, coupled with inline IPS and threat response capabilities to minimize exposure from similar vulnerabilities.



