CVE-2025-13292General

LOWCVSS 7.6 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability in Apigee-X allowed an attacker to gain unauthorized read and write access to Apigee Analytics (AX) data and access logs belonging to other Apigee customer organizations. Apigee-X was found to be vulnerable. This vulnerability was patched in version 1-16-0-apigee-3. No user action is required for this.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-02-04)
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-02-02: 1Mentions · 2026-02-03: 1Mentions · 2026-02-04: 3PoC Mentioned / Linked · 2026-02-02: 1Technical Details · 2026-02-02: 1Technical Details · 2026-02-04: 102-0202-0302-04
Signal classification2 categories
General
360.0%
Disclosure
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-021
Disclosure1
2026-02-031
General1
2026-02-043
Disclosure1General2
Full discourse5 posts
  • OmerAF@omer_asfu
    Disclosure

    👼GatewayToHeaven (CVE-2025-13292). I discovered a cross-tenant vulnerability in @GoogleCloud's #Apigee, allowing me to access other organizations' data (and sometimes even plaintext JWTs of end users). Below is the full breakdown of the exploit chain⛓️ https://t.co/7gVPbryqjr

    Post summary

    The tweet discloses CVE‑2025‑13292, a cross‑tenant flaw in Google Cloud Apigee that lets attackers read other organizations’ data and JWTs, and provides a link to a detailed exploit chain.

    10111456431960.1K
    516 followersView on X
  • Google VRP (Google Bug Hunters)@GoogleVRP
    General

    Want to see what elite security research looks like? 🌟 @omer_asfu, one of Google Cloud VRP's best, dropped a cross-tenant finding: CVE-2025-13292 (https://nvd.nist.gov/vuln/detail/CVE-2025-13292)

    Post summary

    The tweet announces a cross‑tenant vulnerability (CVE-2025-13292) discovered by a researcher, but offers no further technical detail, PoC, exploit, or patch information.

    241027714923.2K
    40.4K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2010-5139 2 - CVE-2025-21042 3 - CVE-2025-55177 4 - CVE-2025-13292 5 - CVE-2026-21509 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply enumerates a list of trending CVEs without providing any additional context, technical details, or actionable information.

    10030250
    1.7K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『Some of the data contained plaintext access tokens, which could be exfiltrated to potentially impersonate any end user of any organization that uses Apigee.』😨 CVE-2025-13292 GatewayToHeaven: Finding a Cross-Tenant Vulnerability in GCP's Apigee https://omeramiad.com/posts/gatewaytoheaven-gcp-cross-tenant-vulnerability/

    Post summary

    A newly disclosed cross‑tenant flaw in Google Cloud Apigee (CVE‑2025‑13292) could expose plaintext access tokens, enabling potential user impersonation.

    00012364
    6.7K followersView on X
  • VulnTracker@vuln_tracker
    General

    @omer_asfu @googlecloud @GoogleVRP @QuinnyPig @wiz_io You now can see the full detail about this CVE on https://vulntracker.io/cves/CVE-2025-13292 for FREE

    Post summary

    The tweet merely points to a vulnerability tracker for CVE-2025-13292, providing no additional details.

    00010249
    333 followersView on X

Explore more