PT-2026-33223 · Unknown · Oauth2 Proxy

Kodareef5

·

Published

2026-04-15

·

Updated

2026-04-23

·

CVE-2026-40574

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OAuth2 Proxy versions prior to 7.15.2
Description An authorization bypass exists within the email domain enforcement option. An attacker can authenticate using a malformed email claim, such as attacker@evil.com@company.com, to satisfy an allowed domain check for company.com. This issue specifically affects deployments relying on email domain restrictions that accept email claim values from identity providers or claim mappings that do not strictly enforce standard email syntax. The risk is primarily present in self-hosted or custom OIDC environments and federated setups where unexpected claim values can reach the proxy.
Recommendations Update to version 7.15.2 or later. Ensure the configured identity provider is unable to emit malformed or attacker-controlled email claim values.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-OAUTH2-PROXY-2026-40574
CVE-2026-40574
GHSA-C5C4-8R6X-56W3

Affected Products

Oauth2 Proxy