THREATOPS
THREAT OPSThreat News › CVE-2026-75866: Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them

CVE-2026-75866: Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them

medoss_secPublished 2026-08-22

<p>Posted by Timothy Legge on Aug 22</p>========================================================================<br /> CVE-2026-75866 CPAN Security Group<br /> ========================================================================<br /> <br /> CVE ID: CVE-2026-75866<br /> Distribution: Punk-OAuth2<br /> Versions: through 0.03<br /> <br

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/549

Same event, other sources