CVE-2026-57807 – miniOrange OAuth Single Sign On – SSO (OAuth Client)
“When authentication can be bypassed, identity is no longer a security boundary.”
miniOrange has released a security update for OAuth Single Sign On – SSO (OAuth Client) to address CVE-2026-57807, an authentication bypass vulnerability (CWE-288). The vulnerability allows password recovery exploitation through an alternate authentication path or channel, potentially enabling unauthorized access to affected accounts. The issue affects OAuth Single Sign On – SSO (OAuth Client) versions through 38.5.8.
The CVSS score is 9.8, which is Critical severity. Based on the information provided, there is no verified exploitation associated with this vulnerability. Because the issue can lead to unauthorized account access through authentication bypass, organizations should prioritize applying the available update.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-288