Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 19 Dec 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Palantir
Palantir control Panel |
|
| Vendors & Products |
Palantir
Palantir control Panel |
Thu, 18 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Control Panel provides an API for pre-registering into an enrollment and organization prior to a user's first login. The API for creating users checks that the account requesting a user creation has `edit` on the enrollment-level user directory, but is missing a separate check that the enrollment editor has access (or belongs to) the organization that they are adding a user to. | |
| Title | Insufficient permission checks when pre-enrolling users Summary | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Palantir
Published:
Updated: 2025-12-18T19:48:40.936Z
Reserved: 2025-10-31T16:12:53.455Z
Link: CVE-2025-64400
Updated: 2025-12-18T19:48:19.414Z
Status : Deferred
Published: 2025-12-18T20:16:07.177
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-64400
No data.
OpenCVE Enrichment
Updated: 2025-12-19T09:15:36Z