https://seclists.org/oss-sec/2025/q4/269: CVE-2025-58137: Apache Fineract: IDOR via self-service API
Published Dec 11, 2025
·Updated
Affected Software
1 affected component
Apache Fineract<=1.11.0
Frequently Asked Questions
1
What is the severity of CVE-2025-58137?
The severity of CVE-2025-58137 is classified as important.
2
Which versions of Apache Fineract are affected by CVE-2025-58137?
Apache Fineract versions through 1.11.0 are affected by CVE-2025-58137.
3
How do I fix CVE-2025-58137?
CVE-2025-58137 can be fixed by upgrading to Apache Fineract version 1.12.1.
4
What type of vulnerability is CVE-2025-58137?
CVE-2025-58137 is an Authorization Bypass Through User-Controlled Key vulnerability.
5
What is the impact of CVE-2025-58137 on Apache Fineract?
CVE-2025-58137 allows for authorization bypass via the self-service API, potentially compromising user data.