Authentication Bypass by Spoofing in Wildfly Elytron - CVE-2026-85511

 

Authentication Bypass by Spoofing in Wildfly Elytron - CVE-2026-85511

Published: September 29, 2026


Vulnerability identifier: #VU152750
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-85511
CWE-ID: CWE-290
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass authentication controls.

The vulnerability exists due to missing URL encoding in the Elytron token realm OAuth2 introspection handling when processing token authentication requests. A remote user can provide specially crafted token values to bypass authentication controls.

Only token realms configured both to handle authentication and to validate tokens through an introspection endpoint are affected.


Affected software

Wildfly Elytron

How to mitigate CVE-2026-85511

Install security update from vendor's website.

Wildfly Elytron - addressed in versions 2.6.11, 2.8.6, 2.9.3

External References

Related Security Bulletins