ZeroHour

CVE-2026-48611

CVSS 3.0
9.8 critical
EPSS
4%p90
Published
()
Modified
Description

Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.

Weakness
CWE-287
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news