SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-23922

MEDIUM · CVSS 4.9 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The vulnerability allows a Super Admin to potentially expose the 'Client secret' in the email media OAuth field by configuring a malicious 'Token endpoint', despite the secret being unreadable after saving. Although the severity is rated low, organizations with Super Admin privileges should prioritize addressing this issue to prevent unauthorized access to sensitive OAuth credentials.

CVE
CVE-2026-23922
Severity
MEDIUM
CVSS
4.9
EPSS
0.27%

Original NVD Description

The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.

Related CVEs

Other vulnerabilities affecting the same vendor(s)