OAuth Vulnerability in NamelessMC Software for Minecraft Servers
CVE-2026-34460
5.4MEDIUM
What is CVE-2026-34460?
The NamelessMC web software for Minecraft servers possesses a vulnerability in versions 2.2.4 and earlier, where the OAuth callback handling fails to adequately validate the state parameter on the server side prior to the exchange of the authorization code. This oversight enables attackers to exploit the OAuth mechanism, allowing them to capture valid callback URLs. Consequently, when a victim’s browser navigates to these URLs, their session could be authenticated as belonging to the attacker-linked account, thereby facilitating session swapping and unauthorized access. This critical issue has been addressed in version 2.2.5.
Affected Version(s)
Nameless < 2.2.5
