SB20260728105 - Improper access control in mod_auth_openidc



SB20260728105 - Improper access control in mod_auth_openidc

Published: July 28, 2026

Security Bulletin ID SB20260728105
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper access control (CVE-ID: N/A)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to bypass access restrictions.

The vulnerability exists due to improper access control in local JWT access token validation in OAuth 2.0 Resource Server mode when processing bearer tokens under a Require valid-user authorization policy. A remote user can present a validly signed JWT access token issued for a different audience to bypass access restrictions.

The issue is limited to deprecated Resource Server deployments using local JWT validation without introspection, and has practical consequence where verification key material is shared across multiple audiences.


Remediation

Install update from vendor's website.