CVE-2026-75866: CWE-862 Missing Authorization
Description
Punk::OAuth2::Server versions up to 0.03 for Perl allow clients to obtain access tokens with scopes and grant types beyond those registered due to missing authorization checks. This flaw enables a client to request tokens with arbitrary scopes, which are then accepted and honored by resource servers using Punk::OAuth2::Checker. Clients without secrets authenticate solely by client_id, allowing anyone knowing the client_id to request such tokens.
CVSS v3.1
Score 9.1critical
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Punk::OAuth2::Server versions through 0.03 have a missing authorization path that fails to verify requested scopes and grant types against those registered per client. The server registers scopes and grant_types per client, but token issuance dispatches based on the grant_type in the request body without validating it against the client's registration. The authorize function copies requested scopes into the authorization code without comparing them to registered scopes, relying only on an optional consent hook. Consequently, a registered client can obtain a signed access token carrying any scope it requests. Clients without secrets authenticate using only their client_id, allowing unauthorized token requests by anyone who knows the client_id. Resource servers using Punk::OAuth2::Checker accept and honor these tokens, leading to potential unauthorized access.
Potential Impact
An attacker who knows a client_id can request access tokens with arbitrary scopes and grant types beyond those registered, potentially gaining unauthorized access to protected resources. The vulnerability allows elevation of privileges and unauthorized resource access without requiring client secrets or user consent enforcement.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict knowledge of client_ids and consider additional access controls on resource servers to validate token scopes. Monitor for updates from the vendor or maintainers of Punk::OAuth2::Server for official patches or mitigations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CPANSec
- Date Reserved
- 2026-08-18T11:17:09.339Z
- State
- PUBLISHED
Threat ID: 6a89ad2cacd9273b491d341e
Added to database: 08/22/2026, 14:07:40 UTC
Last enriched: 09/10/2026, 14:37:38 UTC
Last updated: 10/06/2026, 18:48:25 UTC
Views: 66
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.