Improper Isolation Vulnerability in Boruta by Malach IT
CVE-2026-65635
What is CVE-2026-65635?
The Boruta library by Malach IT contains an improper isolation vulnerability within its OpenID module, specifically in the dynamic client registration process. This flaw allows unauthenticated users to register OpenID Connect clients with elevated privileges, bypassing necessary security checks. The vulnerable method Boruta.Openid.register_client/3 forwards input parameters directly to create administrative clients without strict validation, enabling attackers to manipulate critical security settings such as supported grant types, token lifetimes, and more. It’s essential for operators to address this vulnerability by updating to Boruta versions 2.3.7 or higher, which includes the necessary patches to safeguard against unauthorized access.
Affected Version(s)
boruta 2.3.0 < 2.3.7
boruta 85481b706636fe68a43d0b8d3275e2afc7f7fee1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
