Impact
Express Gateway through version 1.16.11 is vulnerable to an authentication bypass in the OAuth 2.0 refresh_token grant; validation fails to confirm the token secret or the issuing client, allowing an attacker with valid client credentials and the identifier of another user's refresh token to obtain that user's access token and impersonate them against any API protected by OAuth 2.0.
Affected Systems
The vulnerability affects the Express Gateway product, a Node.js based API gateway framework. All releases through and including 1.16.11, including the official Docker image, are impacted. No other vendors or product versions are listed in the CNA data for this flaw.
Risk and Exploitability
The flaw scores a CVSS 7.6, indicating high severity. Its EPSS score is unavailable and it is not listed in CISA's KEV catalog. The attack vector is likely remote, using the standard OAuth 2.0 token exchange endpoint; an attacker only needs legitimate client credentials and the target refresh token identifier, no further privileged access. Because validation is bypassed, the attacker can stealthily obtain any user's access token, enabling impersonation of that user on protected APIs.
OpenCVE Enrichment