SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-44506

HIGH · CVSS 8.2 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The /oauth2/register endpoint in Medplum versions 4.1.10 through 5.1.6 is vulnerable to information disclosure, potentially exposing the client_secret of preconfigured OAuth clients when a matching redirect_uri is supplied. This could allow unauthorized access to sensitive resources, making it critical for developers and organizations using Medplum to upgrade to version 5.1.7 immediately to mitigate the risk. Prioritization is essential for those in the healthcare app development sector to protect against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-44506
Severity
HIGH
CVSS
8.2
EPSS
0.21%

Original NVD Description

Medplum is a developer platform that enables development of healthcare apps. In Medplum versions 4.1.10 through 5.1.6, the /oauth2/register endpoint could return the client_secret of preconfigured OAuth clients defined via the defaultOAuthClients server configuration when a matching redirect_uri was provided. This issue has been patched in version 5.1.7.