PT-2026-26780 · Ory · Ory Oathkeeper

Patrik

·

Publicado

2026-03-20

·

Atualizado

2026-03-27

·

CVE-2026-33496

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Ory Oathkeeper (affected versions not specified)
Description Ory Oathkeeper is susceptible to authentication bypass due to cache key confusion within the oauth2 introspection authenticator. The caching mechanism does not differentiate between tokens validated using distinct introspection URLs. An attacker can leverage a valid token to populate the cache and subsequently utilize the same token for rules associated with a different introspection server. This requires multiple oauth2 introspection authenticator servers configured with caching enabled, and the attacker must possess a valid token for one of these servers.
Recommendations Update to the patched version of Ory Oathkeeper. If an immediate update is not feasible, disable caching for oauth2 introspection authenticators.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33496
GHSA-4MQ7-PVJG-XP2R
GO-2026-4799
SUSE-SU-2026:1135-1

Produtos afetados

Ory Oathkeeper