CVE-2025-47411
Java vulnerability analysis and mitigation

Overview

CVE-2025-47411 is a privilege escalation vulnerability in Apache StreamPipes, classified as "Leverage of User ID for Privilege Escalation," that allows a legitimate non-administrator user to gain full administrative control by exploiting a flaw in the user ID creation mechanism and manipulating JWT tokens. It affects Apache StreamPipes versions 0.69.0 through 0.97.0; version 0.98.0 resolves the issue. The vulnerability was disclosed on December 29, 2025 via the oss-security mailing list and published to NVD on January 1, 2026. It carries a CVSS v3.1 base score of 8.1 (High), as assessed by CISA-ADP (Github Advisory, Openwall OSS-Sec).

Technical details

The root cause is improper privilege management (CWE-269) in the user ID creation mechanism of Apache StreamPipes. An authenticated low-privileged user can manipulate the user ID assignment process to swap their username with that of an administrator, then craft or obtain a JWT token reflecting the administrator's identity, effectively bypassing access controls. The attack requires no user interaction and can be performed remotely over the network with only a standard user account. The vulnerability was credited to darren.xuan@telgroup.com.au as the finder, and a researcher published a write-up describing it as a "Chameleon Attack" involving recursive object tampering (Openwall OSS-Sec, Github Advisory).

Impact

Successful exploitation grants a low-privileged attacker full administrative control over the Apache StreamPipes application, enabling unauthorized access to all data pipelines, data tampering, and modification of application configuration. Since StreamPipes is commonly used for industrial IoT and data pipeline management, compromise could affect sensitive operational data and connected systems. The confidentiality and integrity of the application are both highly impacted, though availability is not directly affected by this vulnerability (Github Advisory, Feedly).

Exploitability

There is no public proof-of-concept exploit or evidence of in-the-wild exploitation at this time (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.02% (4th percentile), indicating a low near-term probability of exploitation (Github Advisory). No threat actor attribution has been reported.

Exploitation steps

  1. Obtain a legitimate account: Register or obtain a valid non-administrator account on a vulnerable Apache StreamPipes instance (versions 0.69.0–0.97.0).
  2. Identify target administrator: Enumerate existing users or identify the administrator's username through the application interface or API.
  3. Exploit user ID creation mechanism: Leverage the flaw in the user ID creation process to associate or swap the attacker's user ID with the administrator's username, exploiting the improper privilege management in the account registration or update flow.
  4. Obtain or forge JWT token: Trigger the application to issue a JWT token that reflects the administrator's identity (e.g., by logging in after the username swap or by manipulating the token generation process).
  5. Authenticate as administrator: Use the manipulated JWT token in subsequent API requests to authenticate as the administrator, gaining full control over the StreamPipes application, including data pipeline management, user administration, and configuration changes (Openwall OSS-Sec, Github Advisory).

Indicators of compromise

  • Logs: Unexpected administrator-level actions (pipeline creation/deletion, user management) attributed to accounts that are not known administrators in StreamPipes application logs; login events for administrator accounts from unusual source IPs or at unusual times.
  • Network: API requests to StreamPipes user management or account registration endpoints followed immediately by administrative API calls from the same session or IP; anomalous JWT tokens with administrator claims originating from non-admin user sessions.
  • Application Behavior: Newly created or modified user accounts with administrator privileges not provisioned by legitimate admins; unexpected changes to data pipeline configurations or user roles in the StreamPipes admin panel.

Mitigation and workarounds

The primary remediation is to upgrade Apache StreamPipes to version 0.98.0 or later, which fixes the vulnerability (Github Advisory, Openwall OSS-Sec). If immediate patching is not feasible, restrict network access to StreamPipes instances to trusted networks only and implement enhanced monitoring for unusual administrative account activity or JWT token anomalies. Review and audit existing user accounts for any unauthorized privilege escalation that may have already occurred.

Community reactions

The vulnerability received coverage from multiple cybersecurity news outlets including CyberSecurityNews, SC World, GBHackers, and The Hacker News (in a weekly recap), highlighting the risk of admin account takeover in industrial data pipeline software (SC World, CyberSecurityNews). A researcher published a detailed write-up on Medium describing the attack as the "Chameleon Attack" involving recursive object tampering. Check Point Research included it in their January 5, 2026 threat intelligence report (Check Point). Community discussion on Bluesky and security forums noted the severity of the privilege escalation risk for organizations using StreamPipes in operational environments.

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-73644CRITICAL9.6
  • Java logoJava
  • org.openidentityplatform.opendj:opendj-server-legacy
NoYesAug 13, 2026
CVE-2026-73507HIGH7.5
  • Java logoJava
  • datahub-upgrade
NoYesAug 13, 2026
CVE-2026-49989HIGH7.1
  • Java logoJava
  • io.crate:crate
NoYesAug 14, 2026
CVE-2026-53660HIGH7
  • Java logoJava
  • org.openidentityplatform.openam:openam-core
NoYesAug 14, 2026
CVE-2026-73508MEDIUM5.3
  • Java logoJava
  • camunda-zeebe-8.8
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management