๐Ÿ” CVE Alert

CVE-2026-3531

MEDIUM 6.5

OpenID Connect / OAuth client - Moderately critical - Access bypass - SA-CONTRIB-2026-026

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
6th

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal OpenID Connect / OAuth client allows Authentication Bypass.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0.

CWE CWE-288
Vendor drupal
Product openid connect / oauth client
Ecosystems
Industries
WebMedia
Published Mar 26, 2026
Last Updated Mar 30, 2026
Stay Ahead of the Next One

Get instant alerts for drupal openid connect / oauth client

Be the first to know when new medium vulnerabilities affecting drupal openid connect / oauth client are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Drupal / OpenID Connect / OAuth client
0.0.0 < 1.5.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
drupal.org: https://www.drupal.org/sa-contrib-2026-026

Credits

Kimberley Massey (kimberleycgm) Kimberley Massey (kimberleycgm) Philip Frilling (pfrilling) Damien McKenna (damienmckenna) Greg Knaddison (greggles) Juraj Nemec (poker10)