OAuth Vulnerability in Medplum Developer Platform
CVE-2026-44506
8.2HIGH
What is CVE-2026-44506?
Medplum, a platform for developing healthcare applications, is susceptible to an OAuth vulnerability present in versions 4.1.10 through 5.1.6. This flaw allows an attacker to retrieve the client_secret of preconfigured OAuth clients through the /oauth2/register endpoint if a matching redirect_uri is supplied. The issue has been addressed in version 5.1.7, and users are advised to update to this version to secure their applications.
Affected Version(s)
medplum >= 4.1.10, < 5.1.7
