SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-54072

CRITICAL · CVSS 9.3 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The vulnerability exists in the Authorizer authentication and authorization server, where the `/authorize` endpoint fails to validate the `redirect_uri` against `AllowedOrigins`, allowing unauthenticated attackers to redirect users to malicious URLs and potentially expose sensitive tokens. This critical flaw affects all versions prior to 2.2.1, and organizations using this software should prioritize upgrading to the latest version to mitigate the risk of token leakage and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-54072
Severity
CRITICAL
CVSS
9.3
EPSS
0.27%

Original NVD Description

Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` or `response_type=id_token`, the server appends `access_token`, `id_token`, and `refresh_token` as query parameters and issues a 302 redirect to the attacker-supplied URL. An unauthenticated attacker can obtain the required `client_id` from the public `/graphql?query={meta{client_id}}` endpoint. A partial fix was applied in v2.0.1 to other handlers (`oauth_login`, `verify_email`, `magic_link_login`, `forgot_password`, `invite_members`, `oauth_callback`) but `/authorize` was not included. Version 2.2.1 contains a more complete fix.