CVE-2026-3432

CVSS

No CVSS.

O

n SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided with `credentialAccountUserId` and `providerId` parameters. An unauthenticated attacker can retrieve OAuth access tokens for any user by supplying their user ID and a provider name, effectively stealing credentials to third-party services.

Configurations

No configuration.

History

02 Mar 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-02 13:16

Updated : 2026-03-02 20:29


NVD link : CVE-2026-3432

Mitre link : CVE-2026-3432

CVE.ORG link : CVE-2026-3432


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization