CVE-2026-54072
Authorizer is an open‑source authentication and authorization server. Before version 2.2.1, its /authorize endpoint accepted any redirect_uri, allowing attackers to receive access, ID, and refresh tokens via a malicious redirect. The issue is fixed in v2.2.1 and later.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Authorizer open‑source authentication and authorization server, versions prior to 2.2.1.
Real-world impact
An unauthenticated attacker can obtain access, ID, and refresh tokens by supplying a malicious redirect_uri, enabling them to impersonate users or gain unauthorized access to protected resources.
Why this severity
The CVSS score of 9.3 reflects a network‑based attack with low complexity, no privileges required, user interaction required, and high confidentiality and integrity impact.
What to do about it
- 01Upgrade Authorizer to version 2.2.1 or later.
NVD description
Timeline
- Sep 11, 2026 · 2d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 11, 2026 · 2d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.