Description
Fides is an open-source privacy engineering platform. Prior to version 2.69.1, admin UI user password changes in Fides do not invalidate active user sessions, creating a vulnerability chaining opportunity where attackers who have obtained session tokens through other attack vectors (such as XSS) can maintain access even after password reset. This issue is not directly exploitable on its own and requires a prerequisite vulnerability to obtain valid session tokens in the first place. Version 2.69.1 fixes the issue. No known workarounds are available.
INFO
Published Date :
2025-09-08T21:12:07.626Z
Last Modified :
2025-09-09T13:45:07.885Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2025-57766 vulnerability.
| Vendors | Products |
|---|---|
| Ethyca |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-57766.