Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Kimberley Massey

#41104de 53,638
6.5CVSS total
Vulnerabilidades · 1
PT-2026-23114
6.5
2026-03-04
Drupal · Openid Connect / Oauth Client · CVE-2026-3531
**Name of the Vulnerable Software and Affected Versions** Drupal OpenID Connect / OAuth client versions prior to 1.5.0 **Description** A flaw exists in the OpenID Connect / OAuth client module that could allow for authentication bypass. Specifically, if a user successfully authenticates with their Identity Provider but is denied access to Drupal due to custom code or a server error, their session remains active at the Identity Provider. This can potentially lead to unauthorized access, particularly in shared computing environments, where a user who initially failed to authenticate may gain access through an alternate path. **Recommendations** Update to version 1.5.0 or later.