Feed/CVE-2026-23922
CVE-2026-23922

CVE-2026-23922

Published Aug 18, 2026·Updated Aug 18, 2026

NVD Description

The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free