CVE-2025-57817

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
08/09/2025
Last modified:
10/09/2025

Description

Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the OAuth client creation and update endpoints of the Fides Webserver API do not properly authorize scope assignment. This allows highly privileged users with `client:create` or `client:update` permissions to escalate their privileges to owner-level. Version 2.69.1 fixes the issue. No known workarounds are available.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ethyca:fides:*:*:*:*:*:*:*:* 2.69.1 (excluding)