← Back to CVE search

CVE-2026-48611

OAuth

Description

Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.

CVSS 9.8EPSS 3.8600000000000003%Risk 1.32
View source
Published
2026-06-12 04:17:08
Affected versions
unknown
Type
Web application
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H