Cross-Site Request Forgery in Erlang Ecosystem Foundation oidcc_plug
CVE-2026-66884
What is CVE-2026-66884?
The oidcc_plug library suffers from a Cross-Site Request Forgery vulnerability which allows attackers to manipulate the authorization process without user consent. Due to a lack of proper session handling, the library processes callback requests without the necessary Oidcc.Plug.Authorize session, completely bypassing critical security checks. This flaw permits attackers to gain an authorization code and trick victims into completing authentication flows initiated by the attacker, resulting in unauthorized access to user accounts. The vulnerability notably affects configurations where the same callback is reused for both account linking and login, making it even more susceptible to exploitation. It is crucial for users of oidcc_plug versions from 0.2.0-beta.1 to before 0.5.0 to update their systems to mitigate potential security risks.
Affected Version(s)
oidcc_plug 0.2.0-beta.1 < 0.5.0
oidcc_plug e577ae73b9080693442916043a22d8f05491dd93 < 97d75afc57826dca31989b47d6e2a3c136039917
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
