
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-47411 is a privilege escalation vulnerability in Apache StreamPipes, classified as "Leverage of User ID for Privilege Escalation," that allows a legitimate non-administrator user to gain full administrative control by exploiting a flaw in the user ID creation mechanism and manipulating JWT tokens. It affects Apache StreamPipes versions 0.69.0 through 0.97.0; version 0.98.0 resolves the issue. The vulnerability was disclosed on December 29, 2025 via the oss-security mailing list and published to NVD on January 1, 2026. It carries a CVSS v3.1 base score of 8.1 (High), as assessed by CISA-ADP (Github Advisory, Openwall OSS-Sec).
The root cause is improper privilege management (CWE-269) in the user ID creation mechanism of Apache StreamPipes. An authenticated low-privileged user can manipulate the user ID assignment process to swap their username with that of an administrator, then craft or obtain a JWT token reflecting the administrator's identity, effectively bypassing access controls. The attack requires no user interaction and can be performed remotely over the network with only a standard user account. The vulnerability was credited to darren.xuan@telgroup.com.au as the finder, and a researcher published a write-up describing it as a "Chameleon Attack" involving recursive object tampering (Openwall OSS-Sec, Github Advisory).
Successful exploitation grants a low-privileged attacker full administrative control over the Apache StreamPipes application, enabling unauthorized access to all data pipelines, data tampering, and modification of application configuration. Since StreamPipes is commonly used for industrial IoT and data pipeline management, compromise could affect sensitive operational data and connected systems. The confidentiality and integrity of the application are both highly impacted, though availability is not directly affected by this vulnerability (Github Advisory, Feedly).
There is no public proof-of-concept exploit or evidence of in-the-wild exploitation at this time (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.02% (4th percentile), indicating a low near-term probability of exploitation (Github Advisory). No threat actor attribution has been reported.
The primary remediation is to upgrade Apache StreamPipes to version 0.98.0 or later, which fixes the vulnerability (Github Advisory, Openwall OSS-Sec). If immediate patching is not feasible, restrict network access to StreamPipes instances to trusted networks only and implement enhanced monitoring for unusual administrative account activity or JWT token anomalies. Review and audit existing user accounts for any unauthorized privilege escalation that may have already occurred.
The vulnerability received coverage from multiple cybersecurity news outlets including CyberSecurityNews, SC World, GBHackers, and The Hacker News (in a weekly recap), highlighting the risk of admin account takeover in industrial data pipeline software (SC World, CyberSecurityNews). A researcher published a detailed write-up on Medium describing the attack as the "Chameleon Attack" involving recursive object tampering. Check Point Research included it in their January 5, 2026 threat intelligence report (Check Point). Community discussion on Bluesky and security forums noted the severity of the privilege escalation risk for organizations using StreamPipes in operational environments.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."