Tag

#OAuth2

articleCRITICAL 9.2

Critical OAuth2/OIDC Account Takeover Vulnerability in AshAuthentication

A critical vulnerability (CVE-2026-49757, CVSS 9.2) in AshAuthentication's OAuth2 and OIDC strategies allows unauthenticated remote account takeover via email-based user matching. The vulnerability affects applications using AshAuthentication with OAuth2/OIDC configurations that do not strictly verify email ownership. An attacker can register an account with a victim's email on a vulnerable provider, then gain full local privileges through a standard OAuth flow.

1 source
newsHIGH 8.8

LiteLLM MCP Authentication Bypass via OAuth2 Passthrough Fallback (CVE-2026-59822)

LiteLLM's MCP Streamable HTTP endpoint is vulnerable to an authentication bypass attack via OAuth2 passthrough fallback, allowing an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. This issue is fixed in version 1.84.0. A CVSS score of 8.8 indicates high severity.

1 source
articleCRITICAL 9.1

Critical CSRF Vulnerability in Mojolicious::Plugin::Web::Auth::OAuth2 (CVE-2026-9733)

A critical vulnerability (CVE-2026-9733) with a CVSS score of 9.1 has been discovered in Mojolicious::Plugin::Web::Auth::OAuth2 versions up to 0.17. This vulnerability allows an attacker to hijack another user's session through cross-site request forgery (CSRF) due to a predictable state parameter. The vulnerability has not been actively exploited but poses a significant risk due to its high severity and potential impact. Immediate patching or mitigation is recommended.

1 source