OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-57178

HIGH · CVSS 7.4 EPSS 0.16% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The `vk-app` backend of Python Social Auth prior to version 5.0.0 is vulnerable due to its failure to verify callback signatures when the `auth_key` parameter is omitted, allowing attackers to manipulate callback data and impersonate arbitrary VK users. This poses a significant risk for applications relying on this backend for social authentication, as it can lead to unauthorized access and identity spoofing. Developers and organizations utilizing this authentication mechanism should prioritize upgrading to version 5.0.0 or later to mitigate this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-57178
Severity
HIGH
CVSS
7.4
EPSS
0.16%

Original NVD Description

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. Applications using this backend could treat unsigned attacker-controlled data as a verified VK identity. An attacker could choose callback fields such as `viewer_id`, `access_token`, `api_id`, and `api_result`, potentially allowing authentication as an arbitrary VK user ID. The issue affects only applications using the `vk-app` backend. The issue has been fixed in version 5.0.0 by requiring `auth_key` to be present and valid before callback data is trusted.