logo

CVE-2025-47411: Critical Apache StreamPipes Flaw Allows Standard Users to Seize Admin Control

ID: 1b0e6ce8-0f9a-5a31-85f7-37f8a7c0cd95

STIX ID: report--1b0e6ce8-0f9a-5a31-85f7-37f8a7c0cd95

Feed Name: securityonline.info

Threat Score
68/100

Date Published: 2025-12-31

Date Updated: 2026-04-22

Author: Ddos

...
...

The Apache Software Foundation disclosed CVE-2025-47411: a logic flaw in Apache StreamPipes (versions 0.69.0–0.97.0) that lets a legitimate non-admin user manipulate JWT tokens to swap their username with an administrator and gain full administrative control; this could enable data tampering and disruption in Industrial IoT environments—users are advised to upgrade to version 0.98.0 which includes the fix.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.