Sceawere
Vulnerability Detail
CVE-2026-97274UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
OAuth SSO Unauthenticated Bypass
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 3h ago
- Vendor
- miniOrange
- Product
- OAuth Single Sign On – SSO (OAuth Client)
- Attack Type
- CWE-290 Authentication Bypass by Spoofing
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-09-30T13:17:38.293Z",
"pubdate": "2026-09-30T13:17:38.293Z",
"executiveSummary": "The OAuth Single Sign-On (SSO) (OAuth Client) plugin for versions 7.1.2 and below is susceptible to an unauthenticated authentication bypass vulnerability.\nThis vulnerability stems from flawed implementation logic within the authentication verification mechanism, allowing remote, unauthenticated attackers to bypass identity provider (IdP) validation.\nThe flaw allows unauthorized actors to impersonate legitimate users or gain unauthorized access to the application without providing valid credentials.\nBy manipulating specific OAuth handshake requests or parameters, an attacker can trick the plugin into establishing an authenticated session for an arbitrary user account.\nThe impact is critical, as it effectively nullifies the authentication layer of the SSO integration, potentially granting full access to user accounts, including administrative privileges if targeted.\nThe vulnerability is exploitable over a network without prior authentication, posing a severe risk to the confidentiality, integrity, and availability of the affected system.\nOrganizations relying on this plugin for secure access control are at risk of complete account takeover and unauthorized data exposure until remediation is applied.",
"technicalDetails": "The vulnerability exists within the OAuth Client plugin's authentication verification workflow, specifically concerning how the plugin processes and validates responses from the configured OAuth Identity Provider (IdP).\nIn versions 7.1.2 and below, the plugin fails to properly enforce strict cryptographic verification of the token exchange or improperly handles the redirection and assertion process. The root cause lies in insecure state validation or inadequate validation of the 'state' and 'code' parameters within the OAuth callback URI.\nAn attacker can exploit this by crafting a malicious OAuth callback request. Since the plugin does not adequately cross-reference the incoming callback with the original initiation request, an attacker can supply an arbitrary user identifier or forge a successful assertion response.\nThe attack flow proceeds as follows: First, the attacker identifies the endpoint designated for handling OAuth callbacks. Second, instead of going through the legitimate OAuth flow, the attacker submits a specially crafted request to this endpoint containing fabricated authentication assertions. Because the plugin logic relies on these assertions without verifying their provenance or matching them against a pending transaction, it assumes the identity in the assertion is valid.\nThe application then parses the malicious assertion, identifies the targeted user account, and proceeds to establish an application-level session for that user.\nThis bypass effectively eliminates the requirement for valid credentials. Since the plugin is designed to trust the assertion provided by the IdP, the failure to perform rigorous integrity checks on the callback mechanism allows any assertion format accepted by the plugin to be potentially manipulated.\nThe scope of exploitation is not restricted to specific IdP configurations, as the flaw resides within the client-side handling of the response, making it highly reproducible. The impact after exploitation involves unauthorized session creation, granting the attacker the identity and privileges of the compromised user account within the host application. If an administrative account is targeted, the attacker gains full control over the application environment, allowing for data exfiltration, configuration changes, and further persistence mechanisms."
}