THREAT OPS › Threat News › [NVD] CVE-2026-75866 — Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them.
Punk::OAuth2::Server::Store registers scopes and grant_types per client and documents both as client registratio
[NVD] CVE-2026-75866 — Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them. Punk::OAuth2::Server::Store registers scopes and grant_types per client and documents both as client registratio
CVE-2026-75866 CVSS: None Published: 2026-08-22T14:16:33.700
Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them.
Punk::OAuth2::Server::Store registers scopes and grant_types per client and documents both as client registration. token dispatches on the grant_type in the request body
Indicators of compromise
- CVE-2026-75866cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-75866