CVE-2025-58137: Apache Fineract: IDOR via self-service API
Published Dec 11, 2025
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract.
This issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1.
Users are encouraged to upgrade to version 1.13.0, the latest release.
Affected Software
2 affected components
Apache Fineract<=1.11.0
Apache Fineract<1.12.1
Event History
Dec 12, 2025
CVE Published
via MITRE·09:21 AM
Data Sourced
via MITRE·09:21 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-58137?
CVE-2025-58137 is classified as a high severity vulnerability due to its potential for authorization bypass.
2
How do I fix CVE-2025-58137?
To fix CVE-2025-58137, upgrade Apache Fineract to version 1.12.1 or later.
3
What versions of Apache Fineract are affected by CVE-2025-58137?
Apache Fineract versions up to and including 1.11.0 are affected by CVE-2025-58137.
4
What is the nature of the vulnerability described in CVE-2025-58137?
CVE-2025-58137 is an authorization bypass vulnerability that allows user-controlled keys to bypass security controls.
5
Is there a safe version to use after fixing CVE-2025-58137?
Yes, after fixing CVE-2025-58137, it is safe to use version 1.13.0 of Apache Fineract.