CVE-2025-51479: Medium severity Onyx Onyx Enterprise Edition vulnerability
Authorization bypass in updateusergroup in onyx-dot-app Onyx Enterprise Edition 0.27.0 allows remote authenticated attackers to modify arbitrary user groups via crafted PATCH requests to the /api/manage/admin/user-group/id endpoint, bypassing intended curator-group assignment checks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-51479?
CVE-2025-51479 has a high severity rating due to the potential for unauthorized access and modification of user groups.
How do I fix CVE-2025-51479?
To fix CVE-2025-51479, apply the latest security patch provided by Onyx for the Onyx Enterprise Edition.
What are the potential impacts of CVE-2025-51479?
The potential impacts of CVE-2025-51479 include unauthorized modification of user groups and possible escalation of privileges for attackers.
Who is affected by CVE-2025-51479?
Users of Onyx Enterprise Edition version 0.27.0 are affected by CVE-2025-51479.
How does CVE-2025-51479 enable exploitation?
CVE-2025-51479 enables exploitation by allowing remote authenticated attackers to bypass curator-group assignment checks through crafted PATCH requests.