AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-28008

CRITICAL · CVSS 9.8 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The vulnerability affects OAuth Single Sign-On (SSO) implementations in versions 7.0.0 and earlier, allowing unauthenticated attackers to exploit broken authentication mechanisms. This critical flaw could lead to unauthorized access to sensitive user data and systems, making it imperative for organizations using these OAuth Client versions to prioritize immediate remediation. Security teams should assess their environments for affected products and implement necessary updates to mitigate potential exploitation.

CVE
CVE-2026-28008
Severity
CRITICAL
CVSS
9.8
EPSS
0.40%

Original NVD Description

Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.