CVE-2025-13475Low· 3.5▾ SunlitIn multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific SaaS application within one tenant can be incorrectly applied…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 19.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.1%
0.1% → 0.3%
In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific SaaS application within one tenant can be incorrectly applied to SaaS applications with the same name in other tenants, leading to unintended cross-tenant consent sharing.
This vulnerability may result in the exposure of user data across tenants, enabling SaaS applications in different tenants to access and modify information without explicit user authorization. This can lead to unauthorized data access and privacy violations. This vulnerability has no impact if the deployment does not support multi-tenancy.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-82269High· 8.1Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware
CVE-2026-93928High· 7.3Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc
CVE-2026-58269High· 8.1Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing
CVE-2026-75627Critical· 9.8Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments
CVE-2026-81868Medium· 6.5Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications
CVE-2026-62101Critical· 9.8Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.