Junglewise Threat Intelligence

CVE-2025-13003: Aksis AxOnboard authorization bypass via user-controlled key

CVE-2025-13003 · Severity: high · CVSS 7.6 · Published 2025-12-11

Executive brief

Aksis AxOnboard, a digital onboarding and customer management platform, contains a security flaw that allows users to bypass authorization controls. By manipulating specific identifiers or keys within the application, an authenticated user could gain unauthorized access to data or perform actions they are not permitted to do. This could lead to the unauthorized modification of customer records or the exposure of sensitive onboarding information.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability, classified as CWE-639 (Authorization Bypass Through User-Controlled Key), exists in Aksis AxOnboard versions 3.2.0 through 3.2.x. The flaw resides in the application's failure to properly validate that the user requesting a specific resource or performing an action has the necessary permissions for the identifier (key) provided in the request. A remote attacker with low-privileged credentials can manipulate these keys to access or modify records belonging to other users or the system. The vulnerability is exploitable over the network without user interaction. A fix is available in version 3.3.0.

Affected products

  • Aksis Computer Services and Consulting Inc. AxOnboard from 3.2.0 before 3.3.0

Timeline

  • 2025-12-11: disclosed
  • 2025-12-11: advisory

References