OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-93354

HIGH · CVSS 8.1 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects Exchange products using Taskview Community versions prior to 1.56.0, allowing unauthenticated attackers to exploit the OAuth 2.0 Dynamic Client Registration endpoint. By sending a POST request, attackers can register arbitrary OAuth clients, enabling them to capture authorization codes and access tokens, which could lead to full account takeover. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access to sensitive user data.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-93354
Severity
HIGH
CVSS
8.1
EPSS
0.27%
Exchange

Original NVD Description

Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registration endpoint, which is enabled by default and requires no authentication. Attackers can send a POST request to the registration endpoint to obtain a client_id and client_secret, then craft a malicious authorization link pointing to an attacker-controlled redirect URI to capture authorization codes and exchange them for access tokens granting full API access to victim account data.