In July 2025, researchers at Clutch Security found that OneLogin, a widely used cloud identity provider, returned more than it should from one of its APIs. The endpoint that lists a tenant's applications, /api/2/apps, included the client secret of every OpenID Connect (OIDC) application in plain text. Anyone with valid OneLogin API credentials, which organisations often share with vendors and contractors for integrations, could therefore collect the secrets for every OIDC application in the tenant and use them to impersonate those applications. Tracked as CVE-2025-59363 with a CVSS score of 7.7, the flaw was fixed in OneLogin release 2025.3.0. Clutch estimated that 110,000 to 275,000 OIDC applications across OneLogin's more than 5,500 enterprise customers could have been affected, based on typical deployments. Clutch found no evidence of exploitation, and OneLogin confirmed that no customers were impacted.
Key takeaways
- OneLogin's application listing API returned OIDC client secrets in plain text to any caller with valid API credentials (CVE-2025-59363, CVSS 7.7).
- API keys shared with vendors could therefore reveal the secrets of every OIDC application in a tenant, not only the ones the vendor needed.
- Stolen client secrets would let an attacker impersonate applications and obtain tokens for integrated services.
- OneLogin fixed the flaw in release 2025.3.0; Clutch found no exploitation and OneLogin said no customers were impacted.
- The identity lesson: one broadly scoped API key can unlock many other machine secrets, so API credentials need least privilege and every secret needs a clear owner.
At a glance
| Organisations | OneLogin (One Identity); OneLogin customers using OIDC applications |
|---|---|
| When | Reported 18 July 2025; fix confirmed 9 September 2025; disclosed by Clutch Security 1 October 2025 |
| Attacker | None known. Found by Clutch Security |
| Entry point | A valid OneLogin API credential calling the /api/2/apps endpoint |
| Identities abused | OneLogin API credentials (often shared with vendors); OIDC application client secrets returned by the API |
| Impact | Potential exposure of client secrets for all OIDC applications in a tenant; no exploitation found |
| Category | NHI. Incident class: vulnerability found by researchers (vulnerability, no confirmed breach) |
What happened
Clutch Security was assessing identity provider APIs when it noticed that OneLogin's application listing endpoint "was returning more data than expected." The endpoint "is designed to list applications configured within a tenant. While this endpoint should return only metadata and public identifiers, it inadvertently included sensitive client_secret values in the API response." ZeroPath noted that, under OIDC best practice, a client secret should be shown only when the application is registered, not returned in routine queries.
The attack required valid API credentials, but Clutch argued that was a low bar in practice: "Organizations commonly share OneLogin API keys with third-party vendors for integration purposes. Due to OneLogin's RBAC model, API keys typically have broad access to all endpoints." It added that OneLogin did not support IP allow-listing for API access, so a leaked vendor key could be used from anywhere. With the secrets, "attackers could impersonate legitimate applications and perform OAuth flows to obtain access tokens, effectively bypassing authentication controls for integrated services."
Clutch reported the issue on 18 July 2025. OneLogin acknowledged it on 22 July and confirmed it on 30 July; after an escalation on 27 August, a technical call on 9 September confirmed the fix in release 2025.3.0. "We found no evidence of active exploitation, and OneLogin confirmed that no customers were impacted by this vulnerability during the vulnerable period," Clutch wrote. Beyond Identity used the flaw to argue against relying on shared secrets such as client credentials and API keys.
Timeline
| Date | Event |
|---|---|
| 18 July 2025 | Clutch Security reports the vulnerability to OneLogin. |
| 30 July 2025 | OneLogin confirms the vulnerability. |
| 9 September 2025 | A technical call confirms the fix in OneLogin 2025.3.0. |
| 13 September 2025 | ZeroPath publishes a technical summary of CVE-2025-59363. |
| 1 October 2025 | Clutch Security publishes its findings. |
How it happened: the identity attack path
- Obtain an API credential. An attacker uses a OneLogin API key, for example one shared with a vendor.
- Request a token. The key is exchanged for a bearer token through the client credentials flow.
- List applications. The
/api/2/appsendpoint returns all applications, including client secrets. - Harvest secrets. The attacker collects OIDC client secrets for every application in the tenant.
- Impersonate applications. The secrets are used to obtain tokens for integrated services.
Impact
- Potential: exposure of client secrets for all OIDC applications in any affected tenant; Clutch estimated 110,000 to 275,000 applications.
- Actual: no exploitation found; OneLogin said no customers were impacted.
- Fix: OneLogin release 2025.3.0.
What this means for NHI governance
This flaw links two kinds of non-human identity. API keys give integrations access to the identity provider, and OIDC client secrets let applications authenticate. Because the API key could read the client secrets, the security of every application depended on every API key, including keys held by vendors. That is exactly the kind of hidden dependency identity teams need to map.
The practical lessons are to scope API credentials to the endpoints each integration needs, inventory who holds them, rotate client secrets after any doubt, and prefer credential types that cannot be copied, such as private key JWT authentication, over shared secrets where the platform supports them. See our API Key Management Guide and OAuth 2.0 and OpenID Connect Guide.
Recommendations
- Update and rotate. Confirm your tenant runs OneLogin 2025.3.0 or later and consider rotating OIDC client secrets. See the Leaked Credential Response Playbook.
- Scope API credentials tightly. Give each integration only the permissions it needs. See our API Key Management Guide.
- Inventory vendor-held keys. Know which third parties hold identity provider API keys. See the Third-Party Access Guide.
- Prefer stronger client authentication. Use private key or certificate-based client authentication where supported. See the OAuth 2.0 and OpenID Connect Guide.
- Monitor API usage. Alert on unusual enumeration of applications. See the ITDR Guide.
Frequently asked questions
Was OneLogin breached?
No breach was found. Clutch Security discovered a vulnerability (CVE-2025-59363) that could expose OIDC client secrets through the API. OneLogin fixed it and confirmed no customers were impacted.
What is CVE-2025-59363?
A OneLogin flaw in which the /api/2/apps endpoint returned OIDC application client secrets to any caller with valid API credentials. It has a CVSS score of 7.7.
What should OneLogin customers do?
Confirm they are on release 2025.3.0 or later, review which API keys exist and who holds them, and consider rotating OIDC client secrets.
Related NHI Mgmt Group resources
Entra ID Actor Token Flaw 2025 · Salesloft Drift Breach 2025 · API Key Management Guide · OAuth 2.0 and OpenID Connect Guide · Third-Party Access Guide
How NHI Mgmt Group can help
Identity provider API keys can reach far more than their owners realise. We help teams map what each machine credential can access, scope it down and track who holds it. See our NHI and AI agent security training.
References
- ZeroPath: OneLogin OIDC Client Secret Exposure (CVE-2025-59363): Brief Summary and Technical Review (13 September 2025)
- Clutch Security: OneLogin, Many Secrets: Clutch Uncovers Critical API Vulnerability Exposing Client Credentials (1 October 2025)
- Beyond Identity: CVE-2025-59363: OneLogin Breach Highlights Urgent Need to Secure Non-Human Identities (3 October 2025)