CRITICALVulnerability

CVE-2026-50628

A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.

Properties

severity
CRITICAL
score
9.8
cve_id
CVE-2026-50628
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
published_at
2026-06-12T10:16:22.710
last_modified
2026-08-07T13:16:50.697

Related Entities (4)

HAS_WEAKNESS (2)

[Weakness]Improperly Implemented Security Check for Standard
[Weakness]Improper Input Validation

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-50628 — Ninja Signal Threat Intelligence | Ninja Signal