THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-75866 — Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them. Punk::OAuth2::Server::Store registers scopes and grant_types per client and documents both as client registratio

[NVD] CVE-2026-75866 — Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them. Punk::OAuth2::Server::Store registers scopes and grant_types per client and documents both as client registratio

mednvdPublished 2026-08-22

CVE-2026-75866 CVSS: None Published: 2026-08-22T14:16:33.700

Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them.

Punk::OAuth2::Server::Store registers scopes and grant_types per client and documents both as client registration. token dispatches on the grant_type in the request body

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-75866

Same event, other sources