What is CVE-2025-13909?
CVE-2025-13909 allows authentication bypass of tenant isolation in multi-tenant systems when using Email OTP, SMS OTP, or Magic Link, potentially exposing users' personally identifiable information to other tenants. Immediate enforcement of strict tenant validation in authentication requests and an audit of affected factors are required.
Azərbaycanca: CVE-2025-13909 multi-tenant sistemlərdə Email OTP, SMS OTP və ya Magic Link autentifikasiya metodları zamanı təsdiqləmə zəifliyinə görə istifadəçilərin şifrəli şəxsi məlumatlarının digər təşkilatlar tərəfindən əlçatan olmasına səbəb ola bilər. Təcili olaraq autentifikasiya sorğularında ciddi tenant izolyasiyası tətbiq edilməli və təsirlənən autentifikasiya faktorları audit edilməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which authentication methods are affected by CVE-2025-13909?
This vulnerability affects Email OTP, SMS OTP, and Magic Link authentication methods.
What can an attacker gain by exploiting CVE-2025-13909?
An attacker can make users' personally identifiable information accessible to other tenants in multi-tenant systems.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.