CyberSec.Space Logo
Back to CVE Browser

CVE-2026-50628

PENDING
N/A
CVSS Severity Score
EPSS Score0.0340%
EPSS Percentile8.63th
PublishedJun 12, 2026
Last ModifiedJun 12, 2026

Vulnerability Description

A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

Related Vulnerabilities