CVE-2026-101271

Status: Received

Description

OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled.

Published
September 29, 2026 1:17 PM
Last Modified
September 29, 2026 3:17 PM
Source
655498c3-6ec5-4f0b-aea6-853b334d05a6

Weaknesses (CWE)

CWE-613

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.