CVE-2026-9084
MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based on the email claim w
CVSS
—
No CVSS
EPSS
0.2%
p8
KEV
—
Exploit Today
2
0-100
Published: May 20, 2026 · Last modified: Jul 23, 2026 · CWE-287
0.2%EPSS · 30 days0.2%
2026-07-102026-08-07
MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based on the email claim when the local account had no stored sub value. Under insecure or untrusted IdP configurations where email ownership is not enforced, an attacker with a valid OIDC token could assert a victim’s email address and authenticate as that user, leading to account takeover.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-480399.1 CRI—
——0Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streamable HTTP requests to downstream MCP tool handlers without issuing a `401` response, allowing any network-reachable caller to invoke MCP tools without authentication. When no per-request credential is present, tool handlers fall back to the `META_ACCESS_TOKEN` environment variable, and when the downstream Meta Graph API call fails, `api.py:263–269` serialises the raw `httpx` request URL—including the operator's `access_token` as a query parameter—into the JSON-RPC response body, delivering the credential to the unauthenticated caller. Version 1.0.109 fixes the issue.23hCVE-2026-567937.7 HIG—
——0Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.14hCVE-2026-160308.1 HIG3.5%
——1The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts.1dCVE-2026-142059.8 CRI3.2%
——1The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment.1dCVE-2026-628969.6 CRI31.8%
——10Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.1dCVE-2026-5616210.0 CRI39.8%
——12Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.14h