AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-57818

HIGH · CVSS 8.1 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A race condition in JCacheCodeDataProvider enables attackers to exploit concurrent requests to redeem a single authorization code multiple times, leading to the issuance of multiple valid access tokens. This vulnerability poses a significant risk to systems relying on authorization code flows, potentially allowing unauthorized access to sensitive resources. Organizations using affected versions should prioritize upgrading to versions 4.2.3, 4.1.8, or 3.6.12 to mitigate this high-severity issue.

CVE
CVE-2026-57818
Severity
HIGH
CVSS
8.1
EPSS
0.34%

Original NVD Description

A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple distinct, valid access tokens. Users are recommended to upgrade to versions 4.2.3, 4.1.8 or 3.6.12, which fix this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)