logo

OneLogin, Many Issues: How I Pivoted from a Trial Tenant to Compromising Customer Signing Keys

ID: 9eb56791-8ed5-52b8-9f6f-82c1fba50d36

STIX ID: report--9eb56791-8ed5-52b8-9f6f-82c1fba50d36

Feed Name: SpecterOps Blog

Threat Score
78/100

Date Published: 2025-06-10

Date Updated: 2026-04-30

Author: Julian Catrambone

...
...

A security researcher discovered that OneLogin's AD Connector exposed sensitive configuration data — including directory tokens, an API key, a base64 signing key used to sign JWTs, and AWS credentials — via an ADC configuration API and customer logs sent to an unclaimed S3 bucket. Using those artifacts the researcher was able to generate valid JWTs to impersonate arbitrary users in affected OneLogin tenants and access assigned applications; the researcher claimed the S3 bucket, confirmed another customer's data was leaking there, and engaged in coordinated disclosure with OneLogin while providing defensive guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.