Improper access control in mod_auth_openidc - #VU142425
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to revoke another user's tokens at the identity provider.
The vulnerability exists due to improper access control in front-channel logout handling when processing a logout request identified only by a sid and carrying no authenticated session. A remote attacker can send a crafted logout request naming a known sid to revoke another user's tokens at the identity provider.
Exploitation requires knowledge of a valid sid.