Parameter Substitution Vulnerability in EAP's Elytron Token-Realm
CVE-2026-85511

4.2MEDIUM

What is CVE-2026-85511?

A vulnerability exists in EAP's Elytron when using a security domain backed by an Elytron token-realm with OAuth2 introspection. This flaw arises from insufficient URL encoding, allowing for potential parameter substitution. Attackers could exploit this weakness to manipulate parameters in URL requests, potentially leading to unauthorized access or other security breaches. It is crucial for organizations utilizing EAP's Elytron to implement mitigations to protect against this vulnerability.

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.