Control Panel provides an API for pre-registering into an enrollment and organization prior to a user's first login. The API for creating users checks that the account requesting a user creation has `edit` on the enrollment-level user directory, but is missing a separate check that the enrollment editor has access (or belongs to) the organization that they are adding a user to.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Control Panel provides an API for pre-registering into an enrollment and organization prior to a user's first login. The API for creating users checks that the account requesting a user creation has `edit` on the enrollment-level user directory, but is missing a separate check that the enrollment editor has access (or belongs to) the organization that they are adding a user to. | |
| Title | Insufficient permission checks when pre-enrolling users Summary | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Palantir
Published: 2025-12-18T19:32:30.241Z
Updated: 2025-12-18T19:48:40.936Z
Reserved: 2025-10-31T16:12:53.455Z
Link: CVE-2025-64400
Updated: 2025-12-18T19:48:19.414Z
Status : Received
Published: 2025-12-18T20:16:07.177
Modified: 2025-12-18T20:16:07.177
Link: CVE-2025-64400
No data.