Impact
A vulnerability in Peppermint Lab’s Peppermint product permits any authenticated user who is not an administrator to alter the platform’s global OIDC/SSO configuration through an unsecured endpoint. The bug allows this endpoint to change the OIDC issuer without performing an administrative role check, enabling the attacker to redirect all SSO logins to an attacker‑controlled identity provider. If successful, the attacker can harvest credentials for every user that authenticates through the platform, effectively compromising the entire user base. The weakness is a classic broken access control error that facilitates both privilege escalation within the platform and subsequent credential theft.
Affected Systems
The flaw exists in releases of Peppermint that contain the code commit identified as ba6e217. Any deployment running that commit, or any successor version that has not applied the fix, is considered affected. The product in question is Peppermint Lab’s Peppermint platform.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. While EPSS data is not available, the nature of the flaw—requiring only authenticated non‑admin access—suggests that exploitation is relatively straightforward, relying on common credential usage patterns. The vulnerability is not listed in the CISA KEV catalog, but that does not diminish its potential impact, given the ability to intercept all SSO traffic. Attackers could execute this exploit remotely by simply logging in with any valid non‑admin account and sending a configuration request to the vulnerable endpoint.
OpenCVE Enrichment