Cross-Site Request Forgery in Erlang Ecosystem Foundation oidcc_plug
CVE-2026-66884

2.1LOW

What is CVE-2026-66884?

The oidcc_plug library suffers from a Cross-Site Request Forgery vulnerability which allows attackers to manipulate the authorization process without user consent. Due to a lack of proper session handling, the library processes callback requests without the necessary Oidcc.Plug.Authorize session, completely bypassing critical security checks. This flaw permits attackers to gain an authorization code and trick victims into completing authentication flows initiated by the attacker, resulting in unauthorized access to user accounts. The vulnerability notably affects configurations where the same callback is reused for both account linking and login, making it even more susceptible to exploitation. It is crucial for users of oidcc_plug versions from 0.2.0-beta.1 to before 0.5.0 to update their systems to mitigate potential security risks.

Affected Version(s)

oidcc_plug 0.2.0-beta.1 < 0.5.0

oidcc_plug e577ae73b9080693442916043a22d8f05491dd93 < 97d75afc57826dca31989b47d6e2a3c136039917

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mathias Polligkeit
Mathias Polligkeit
Jonatan Männchen / EEF
Jonatan Männchen / EEF
.