OAuth Vulnerability in NamelessMC Software for Minecraft Servers
CVE-2026-34460

5.4MEDIUM

Key Information:

Vendor

Namelessmc

Status
Vendor
CVE Published:
2 June 2026

What is CVE-2026-34460?

The NamelessMC web software for Minecraft servers possesses a vulnerability in versions 2.2.4 and earlier, where the OAuth callback handling fails to adequately validate the state parameter on the server side prior to the exchange of the authorization code. This oversight enables attackers to exploit the OAuth mechanism, allowing them to capture valid callback URLs. Consequently, when a victim’s browser navigates to these URLs, their session could be authenticated as belonging to the attacker-linked account, thereby facilitating session swapping and unauthorized access. This critical issue has been addressed in version 2.2.5.

Affected Version(s)

Nameless < 2.2.5

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.