Authentication Bypass by Spoofing in Wildfly Elytron - CVE-2026-85511
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote user to bypass authentication controls.
The vulnerability exists due to missing URL encoding in the Elytron token realm OAuth2 introspection handling when processing token authentication requests. A remote user can provide specially crafted token values to bypass authentication controls.
Only token realms configured both to handle authentication and to validate tokens through an introspection endpoint are affected.