CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2025-47411
8.80.02%

Pipe Dreams: Stealing Admin Privileges in Apache StreamPipes (CVE-2025-47411)

Alon Barad
Alon Barad
Software Engineer

Jan 2, 2026·6 min read·1 visit

PoC Available

Executive Summary (TL;DR)

Apache StreamPipes versions prior to 0.98.0 contain a critical flaw where a standard user can 'swap' their username with an administrator's. Due to improper validation during profile updates, the system accepts the change. Upon the next token issuance, the identity provider mints a JWT with full administrative privileges based on the hijacked username. This allows complete takeover of the IIoT platform.

A critical privilege escalation vulnerability in Apache StreamPipes allowing authenticated non-admin users to seize administrative control by exploiting a logic flaw in user identity management.

Official Patches

ApacheOfficial Release Notes for 0.98.0 containing the fix.
Apache Mailing ListOfficial Disclosure Thread

Technical Appendix

CVSS Score
8.8/ 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
EPSS Probability
0.02%
Top 100% most exploited

Affected Systems

Apache StreamPipes 0.69.0Apache StreamPipes 0.70.0Apache StreamPipes 0.90.0Apache StreamPipes 0.93.0Apache StreamPipes 0.95.0Apache StreamPipes 0.97.0

Affected Versions Detail

Product
Affected Versions
Fixed Version
Apache StreamPipes
Apache Software Foundation
< 0.98.00.98.0
AttributeDetail
CVE IDCVE-2025-47411
CVSS v4.08.8 (Critical)
CWECWE-269 (Improper Privilege Management)
Attack VectorNetwork (Authenticated)
Affected Versions< 0.98.0
EPSS Score0.00020

MITRE ATT&CK Mapping

T1078Valid Accounts
Initial Access
T1098Account Manipulation
Persistence
T1548Abuse Elevation Control Mechanism
Privilege Escalation
CWE-269
Improper Privilege Management

The application does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Known Exploits & Detection

HypotheticalExploitation involves standard API manipulation using Burp Suite or curl to modify the username field to a privileged account name.

Vulnerability Timeline

Disclosed on OSS Security mailing list
2025-12-29
CVE-2025-47411 Published
2026-01-01
Fixed version 0.98.0 available
2026-01-02

References & Sources

  • [1]NVD Entry
  • [2]SecurityOnline Analysis
  • [3]OSS-Security Mailing List

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.