PT-2026-39854 · Outline · Outline

Published

2026-05-11

·

Updated

2026-05-12

·

CVE-2026-43886

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Outline versions 0.84.0 through 1.6.1
Description A logic error exists in the validateScope() function within the OAuthInterface. The function utilizes Array.some() to validate requested OAuth scopes, which results in the entire scope array being accepted if at least one scope is valid. This allows an attacker to smuggle a wildcard * scope by requesting scope=read *, effectively escalating a read-only OAuth token to full unrestricted API access, including write, delete, and admin operations.
Recommendations Update to version 1.7.0.

Exploit

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2026-43886

Affected Products

Outline