Missing Authentication Vulnerability in Taskview Community by Gimanh
CVE-2026-93354
8.5HIGH
What is CVE-2026-93354?
Taskview Community versions prior to 1.56.0 are vulnerable to a missing authentication flaw that exposes the OAuth 2.0 Dynamic Client Registration endpoint. This vulnerability allows unauthenticated attackers to register arbitrary OAuth clients, enabling them to gain unwanted access to user accounts. By sending a POST request to the registration endpoint, attackers can obtain valid client IDs and secrets. They can subsequently create a malicious authorization link directed to a URI that they control, capturing authorization codes and exchanging them for access tokens, ultimately granting them full access to victim account data.
Affected Version(s)
taskview-community 0 < 1.56.0
