Skip to main content
EPSS 0.5%top 60%

CVE-2026-75866: CWE-862 Missing Authorization

0
Critical
Published: 08/22/2026 (08/22/2026, 13:52:49 UTC)
Source: CVE Database V5

Description

Punk::OAuth2::Server versions up to 0.03 for Perl allow clients to obtain access tokens with scopes and grant types beyond those registered due to missing authorization checks. This flaw enables a client to request tokens with arbitrary scopes, which are then accepted and honored by resource servers using Punk::OAuth2::Checker. Clients without secrets authenticate solely by client_id, allowing anyone knowing the client_id to request such tokens.

CVSS v3.1

Score 9.1critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 14:37:38 UTC

Technical Analysis

Punk::OAuth2::Server versions through 0.03 have a missing authorization path that fails to verify requested scopes and grant types against those registered per client. The server registers scopes and grant_types per client, but token issuance dispatches based on the grant_type in the request body without validating it against the client's registration. The authorize function copies requested scopes into the authorization code without comparing them to registered scopes, relying only on an optional consent hook. Consequently, a registered client can obtain a signed access token carrying any scope it requests. Clients without secrets authenticate using only their client_id, allowing unauthorized token requests by anyone who knows the client_id. Resource servers using Punk::OAuth2::Checker accept and honor these tokens, leading to potential unauthorized access.

Potential Impact

An attacker who knows a client_id can request access tokens with arbitrary scopes and grant types beyond those registered, potentially gaining unauthorized access to protected resources. The vulnerability allows elevation of privileges and unauthorized resource access without requiring client secrets or user consent enforcement.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict knowledge of client_ids and consider additional access controls on resource servers to validate token scopes. Monitor for updates from the vendor or maintainers of Punk::OAuth2::Server for official patches or mitigations.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
CPANSec
Date Reserved
2026-08-18T11:17:09.339Z
State
PUBLISHED

Threat ID: 6a89ad2cacd9273b491d341e

Added to database: 08/22/2026, 14:07:40 UTC

Last enriched: 09/10/2026, 14:37:38 UTC

Last updated: 10/06/2026, 18:48:25 UTC

Views: 66

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses