CVE-2026-85511

MEDIUM Status: Received

CVSS Scores

CVSS v3.x Base Score
4.2
MEDIUM

Description

A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.

Published
September 18, 2026 3:17 PM
Last Modified
September 18, 2026 3:17 PM
Source
[email protected]

Weaknesses (CWE)

CWE-290

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.