CVE-2026-57807 – miniOrange OAuth Single Sign On – SSO (OAuth Client)

CVSS 9.8 CRITICAL Critical - Same Day Deployment

“When authentication can be bypassed, identity is no longer a security boundary.”

miniOrange has released a security update for OAuth Single Sign On – SSO (OAuth Client) to address CVE-2026-57807, an authentication bypass vulnerability (CWE-288). The vulnerability allows password recovery exploitation through an alternate authentication path or channel, potentially enabling unauthorized access to affected accounts. The issue affects OAuth Single Sign On – SSO (OAuth Client) versions through 38.5.8.

The CVSS score is 9.8, which is Critical severity. Based on the information provided, there is no verified exploitation associated with this vulnerability. Because the issue can lead to unauthorized account access through authentication bypass, organizations should prioritize applying the available update.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-288
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.