This issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1.
Users are encouraged to upgrade to version 1.13.0, the latest release.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 18 Dec 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:fineract:*:*:*:*:*:*:*:* |
Sun, 14 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache fineract |
|
| Vendors & Products |
Apache
Apache fineract |
Fri, 12 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 12 Dec 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 12 Dec 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1. Users are encouraged to upgrade to version 1.13.0, the latest release. | |
| Title | Apache Fineract: IDOR via self-service API | |
| Weaknesses | CWE-639 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-12-12T19:35:44.785Z
Reserved: 2025-08-26T00:04:03.552Z
Link: CVE-2025-58137
Updated: 2025-12-12T10:06:26.103Z
Status : Analyzed
Published: 2025-12-12T10:15:49.370
Modified: 2025-12-18T14:55:12.187
Link: CVE-2025-58137
No data.
OpenCVE Enrichment
Updated: 2025-12-14T21:16:25Z