Mmastodon TechnologyCybersecurity first seen 1 d ago, last 1 d ago, peak #4
Critical CVSS 9.8 flaw reported in OAuth SSO plugin
Original: ๐จ CVE-2026-97274 โ CVSS 9.8 CRITICAL Unauthenticated Bypass Vulnerability in OAuth Single Sign On โ SSO (OAuth Client) ๐
A critical vulnerability, CVE-2026-97274, has been disclosed in the OAuth Single Sign On โ SSO (OAuth Client) plugin, carrying a CVSS score of 9.8. The flaw is described as an unauthenticated authentication bypass, meaning attackers would not need credentials to exploit it. Security communities are circulating the advisory as organisations using OAuth-based single sign-on assess their exposure.
Why now: A maximum-severity unauthenticated bypass in a widely used single sign-on tool prompts urgent patching and risk assessment.
CVE-2026-97274OAuth Single Sign On โ SSO (OAuth Client)
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/492027