PT-2025-39827 · Unknown · Obsidian Scheduler
Greg Scharf
·
Published
2025-09-29
·
Updated
2025-12-23
·
CVE-2025-56449
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Obsidian Scheduler versions 5.0.0 through 6.3.0
Description
A security issue exists in the Obsidian Scheduler REST API. If an account is locked out due to not enrolling in Multi-Factor Authentication (MFA), the REST API continues to permit the use of Basic Authentication for administrative tasks. Specifically, the default admin account, even when locked out through the web interface, remains usable via the REST API. This allows for the creation of new privileged users, circumventing MFA protections and weakening the intended security measures. The API endpoints involved allow administrative actions despite the account lockout. The vulnerable parameter is the authentication method allowing Basic Authentication when MFA is required.
Recommendations
For versions 5.0.0 through 6.3.0, restrict the use of Basic Authentication when MFA is enforced.
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Obsidian Scheduler