Improper Isolation Vulnerability in Boruta by Malach IT
CVE-2026-65635

8.3HIGH

Key Information:

Vendor

Malach-it

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-65635?

The Boruta library by Malach IT contains an improper isolation vulnerability within its OpenID module, specifically in the dynamic client registration process. This flaw allows unauthenticated users to register OpenID Connect clients with elevated privileges, bypassing necessary security checks. The vulnerable method Boruta.Openid.register_client/3 forwards input parameters directly to create administrative clients without strict validation, enabling attackers to manipulate critical security settings such as supported grant types, token lifetimes, and more. It’s essential for operators to address this vulnerability by updating to Boruta versions 2.3.7 or higher, which includes the necessary patches to safeguard against unauthorized access.

Affected Version(s)

boruta 2.3.0 < 2.3.7

boruta 85481b706636fe68a43d0b8d3275e2afc7f7fee1

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pascal Knoth
Pascal Knoth
Jonatan Männchen / EEF
.