Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal OpenID Connect / OAuth client allows Authentication Bypass.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0.
Subscriptions
No data.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-contrib-2026-026 |
|
History
Thu, 26 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal OpenID Connect / OAuth client allows Authentication Bypass.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0. | |
| Title | OpenID Connect / OAuth client - Moderately critical - Access bypass - SA-CONTRIB-2026-026 | |
| Weaknesses | CWE-288 | |
| References |
|
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2026-03-26T20:03:48.873Z
Reserved: 2026-03-04T16:42:00.011Z
Link: CVE-2026-3531
No data.
Status : Received
Published: 2026-03-26T21:17:09.283
Modified: 2026-03-26T21:17:09.283
Link: CVE-2026-3531
No data.
OpenCVE Enrichment
No data.
Weaknesses