CVE-2025-34063 | One Identity OneLogin Active Directory Connector up to 6.1.4 JWT Signing Key configuration authentication spoofing (EUVD-2025-19635)
A vulnerability was found in One Identity OneLogin Active Directory Connector up to 6.1.4. It has been classified as critical. This affects an unknown part of the file /api/adc/v4/configuration of the component JWT Signing Key Handler. The manipulation leads to authentication bypass by spoofing.
This vulnerability is uniquely identified as CVE-2025-34063. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.