CVE-2026-107162

CVE-2026-107162 published: Express Gateway through 1.16.11 contains an authentication bypass vulnerability in the OAuth 2.0 refresh_token grant that fails to validate the token secret or issuing client. Attackers with any valid client credentials and the identifier portion of another...

View full NVD advisory → ← Back to CVE watch