CVE-2026-3432

Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
02/03/2026
Last modified:
06/03/2026

Description

On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided with `credentialAccountUserId` and `providerId` parameters. An unauthenticated attacker can retrieve OAuth access tokens for any user by supplying their user ID and a provider name, effectively stealing credentials to third-party services.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sim:sim:*:*:*:*:*:*:*:* 0.5.74 (excluding)


References to Advisories, Solutions, and Tools