CVE-2026-57807
An attacker can bypass authentication in miniOrange’s OAuth Single Sign On client by using an alternate path to trigger password recovery. This flaw allows the attacker to reset passwords or gain access without valid credentials. The vulnerability is present in all versions up to 38.5.8.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) versions from the earliest release through 38.5.8, typically used by organizations that rely on miniOrange for single sign‑on.
Real-world impact
By exploiting this flaw, an attacker could reset user passwords or otherwise gain unauthorized access to protected resources, compromising the confidentiality, integrity, and availability of the affected systems.
Why this severity
The CVSS score of 9.8 reflects that no authentication is required, the attacker can fully compromise confidentiality, integrity, and availability, and the vulnerability is exploitable over the network with low effort.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 10, 2026 · 24d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 13d agoAdvisory updatedThe NVD record was last revised.