9.2
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N
Description
CVE-2026-49757 — AshAuthentication OAuth2/OIDC Account Takeover Proof of Concept for CVE-2026-49757 — a critical vulnerability in AshAuthentication where OAuth2/OIDC callbacks resolved to local user accounts by email address instead of the strategy,...
Basic Information
ID
1EF4AA0B-45D8-513E-B6D6-AF05E52ECFC6
Published
Jun 21, 2026 at 07:03
Modified
Jun 21, 2026 at 07:04