CyberRota Analysis
AI-GeneratedThe vulnerability allows a Super Admin to potentially expose the 'Client secret' in the email media OAuth field by configuring a malicious 'Token endpoint', despite the secret being unreadable after saving. Although the severity is rated low, organizations with Super Admin privileges should prioritize addressing this issue to prevent unauthorized access to sensitive OAuth credentials.
CVE
CVE-2026-23922
Severity
MEDIUM
CVSS
4.9
EPSS
0.27%
Original NVD Description
The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.
Related CVEs
Other vulnerabilities affecting the same vendor(s)