Tag
#OIDC
articleCRITICAL 9.2
Critical OAuth2/OIDC Account Takeover Vulnerability in AshAuthentication
A critical vulnerability (CVE-2026-49757, CVSS 9.2) in AshAuthentication's OAuth2 and OIDC strategies allows unauthenticated remote account takeover via email-based user matching. The vulnerability affects applications using AshAuthentication with OAuth2/OIDC configurations that do not strictly verify email ownership. An attacker can register an account with a victim's email on a vulnerable provider, then gain full local privileges through a standard OAuth flow.
blogHIGH 8.3
Understanding the @hulumi/policies Vulnerability: Bypassing IAM Role Policy Checks with Multiple OIDC Providers
A vulnerability in @hulumi/policies allows IAM roles with multiple OIDC providers to bypass policy checks, potentially leading to overly permissive access. The issue was fixed in version 1.4.0.