Missing Authentication Vulnerability in Taskview Community by Gimanh
CVE-2026-93354

8.5HIGH

Key Information:

Vendor

Gimanh

Vendor
CVE Published:
24 September 2026

What is CVE-2026-93354?

Taskview Community versions prior to 1.56.0 are vulnerable to a missing authentication flaw that exposes the OAuth 2.0 Dynamic Client Registration endpoint. This vulnerability allows unauthenticated attackers to register arbitrary OAuth clients, enabling them to gain unwanted access to user accounts. By sending a POST request to the registration endpoint, attackers can obtain valid client IDs and secrets. They can subsequently create a malicious authorization link directed to a URI that they control, capturing authorization codes and exchanging them for access tokens, ultimately granting them full access to victim account data.

Affected Version(s)

taskview-community 0 < 1.56.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bakhromov
VulnCheck
.