CVE-2026-107162
HIGH
7,6
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
6,8
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: none
Description
AI Translation Available
Express Gateway through 1.16.11 contains an authentication bypass vulnerability in the OAuth 2.0 refresh_token grant that fails to validate the token secret or issuing client. Attackers with any valid client credentials and the identifier portion of another user's refresh token can obtain that user's access token and impersonate them against oauth2-protected APIs.
287
Improper Authentication
DraftCommon Consequences
Security Scopes Affected:
Integrity
Confidentiality
Availability
Access Control
Potential Impacts:
Read Application Data
Gain Privileges Or Assume Identity
Execute Unauthorized Code Or Commands
Applicable Platforms
Technologies:
Not Technology-Specific, Web Based, ICS/OT
https://github.com/ExpressGateway/express-gateway
https://github.com/ExpressGateway/express-gateway/blob/45612814d12f65889ef3bdf8…
https://github.com/ExpressGateway/express-gateway/blob/45612814d12f65889ef3bdf8…
https://github.com/ExpressGateway/express-gateway/issues/1076
https://www.vulncheck.com/advisories/express-gateway-through-1.16.11-oauth-2.0-…