CVE-2026-3432

On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided with `credentialAccountUserId` and `providerId` parameters. An unauthenticated attacker can retrieve OAuth access tokens for any user by supplying their user ID and a provider name, effectively stealing credentials to third-party services.
References
Link Resource
https://www.tenable.com/security/research/tra-2026-13 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:sim:sim:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-02 13:16

Updated : 2026-06-17 10:43


NVD link : CVE-2026-3432

Mitre link : CVE-2026-3432

CVE.ORG link : CVE-2026-3432


JSON object : View

Products Affected

sim

  • sim
CWE
CWE-862

Missing Authorization