Scworld
Critical CVE-2025-47411 Vulnerability in Apache StreamPipes Allows Admin Account Takeovers
First seen 2 Jan 2026, 18:36 UTC
•
•50.2
Export
Article Content
Browse articles
A critical privilege escalation vulnerability, tracked as CVE-2025-47411, has been identified in Apache StreamPipes, affecting versions 0.69.0 through 0.97.0. This flaw allows ordinary users to manipulate JWT authentication tokens to gain admin privileges, potentially leading to complete control over admin accounts. The vulnerability stems from a faulty user identity creation mechanism.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.