Google device grants lost client and permission binding
A researcher reports USD 13,337 for a device-grant authorization-boundary failure.
IDVulnerability family
Account lifecycle, session integrity, identity-provider trust. 16 disclosures · 44 related references · 4 diagrams.
Connected collection
A researcher reports USD 13,337 for a device-grant authorization-boundary failure.
A researcher organization reports a $150,000 base award for an exposed service identity with excessive downstream integration authority.
One recovery report received USD 35,000 across two award events.
Patchstack confirmed a USD 14,400 Zero Day award for an authentication-boundary flaw.
Meta confirms a USD 44,250 total award, including bonuses, for this Quest OAuth account-access report.
Meta confirms a USD 27,200 total award for this account-verification report.
A researcher-published vendor decision documents a USD 70,000 award for CVE-2022-20465.
The cited researcher documents a USD 50,000 award for this finding.
A USD 25,000 researcher-reported award illustrates how differing framework and controller assumptions can remove an OAuth consent boundary.
The researcher reports a $10,000 award for this finding. USD is a contextual currency inference from Facebook’s later official retrospective of its 2019 bounty program, not an explicit denomination in the individual…
The cited researcher documents a USD 30,000 award for this finding.
Shopify confirms a $20,000 award for unauthorized collaborator access caused by automatic account conversion.
A 2013 researcher disclosure reports a $20,000 award for unauthorized recovery-phone binding. Its enduring lesson for 2026 applications is that recovery-factor possession and account-change authority require separate…
The USD 32,500 researcher-reported award illustrates the distinction between message origin and disclosure authority.
A researcher-reported USD 30,000 award documents a cross-product account-linking trust failure.
A USD 66,000 researcher-reported award illustrates how weak message authentication and unsafe rendering can invalidate an SDK trust boundary.
Connected collection
CVE-2026-49443 concerns writable identity-mapping fields in API serializers. Delegated connection-management authority could alter which local user or group a source identity represented. The maintainer reports…
CVE-2026-44681 describes an OIDC error path selecting a response destination before client and destination validation. The maintainer reports an unauthorized browser redirect, explicitly excluding direct disclosure of…
Use this guide to review machine identity design: favor short-lived role credentials for workloads, limit permissions to required actions and resources, and retire unnecessary access. It also explains policy validation,…
The maintainer disclosure for CVE-2026-53518 identifies separated reading and deletion of a single-use OAuth authorization record. Under concurrent processing, multiple successful consumers could receive independent…
CVE-2026-53516 concerns implicit linking to an unverified local account. Provider-side email verification was allowed to confer legitimacy on previously stored local credentials. The resulting merged identity could…
Personal SCIM providers could lack an owner, while management checks rejected mismatched ownership only when an owner existed. Missing identity binding therefore admitted unrelated authenticated users. The maintainer…
GHSA-4f45-qmjf-82cv describes account-access links whose configured seconds were interpreted as days. The maintainer reports unused email-verification, password-reset and new-user setup tokens surviving their intended…
Explains Chrome’s conditional admission of no-store pages to the back/forward cache. A restored page resumes in-memory document state rather than performing a fresh network load. The guide describes eviction safeguards…
Research on CVE-2026-71505 describes inconsistent authorization between reading and modifying company portal accounts. A role-level check did not establish authority over the particular company. In researcher-owned…
GHSA-7qfj-82q8-frw6 describes inconsistent account-disable enforcement across authentication methods. Existing browser or remembered sessions could retain API authority because refreshed permissions did not also…
GHSA-v8jx-vq6p-jq52 describes an API permission gap between viewing a submission and changing contact authorship. The maintainer reports that reviewers and program-committee members could obtain author-level access to…
The maintainer confirms that project-level MCP authentication did not authorize later file reads. Resource handlers reached storage without retaining user and project restrictions. A local two-user demonstration showed…
CVE-2026-31944 describes an MCP OAuth callback that trusted cached initiator identity without authenticating the returning browser or checking identity continuity. The advisory describes third-party credentials being…
Form elicitation excludes secrets. URL elicitation places sensitive interactions outside the MCP client and model context, with the requesting server and destination visible to the user. Agreeing to open the interaction…
Server permission challenges shape what a general-purpose MCP client requests. Broad discovery metadata and accumulated scopes can enlarge delegated authority. Token scopes still require application-side authorization.
CVE-2026-54305 concerns authenticated Dynamic Credentials operations missing workflow and credential ownership or scope checks. Maintainers report unauthorized credential metadata access, OAuth identity replacement and…
CVE-2026-33665 describes local-account linkage that trusted a matching LDAP email attribute. The maintainer reports persistent access to the linked account, including administrator authority, even after the directory…
The maintainer reports that initial OAuth authorization preserved resource-specific consent, while refresh grants checked registration without preserving that binding. A client could consequently receive authority over…
An evaluation of 27 services and a 100-participant user study examines missing context, explicit consent and post-login control in cross-device authentication. Conceptual boundary: an already trusted device may approve…
CVE-2026-41574 describes provider adapters converting email presence or fallback profile attributes into a verification claim. An account-linking consumer then treated that normalized claim as ownership evidence. The…
Defines authorization in terms of subject, object, operation and environmental attributes evaluated against policy. Enterprise considerations connect business rules to machine-enforced decisions, attribute authorities…
GHSA-wr5q-7wxw-x568 describes client-address metadata acquiring authority to waive authentication without verified transport-peer and intermediary provenance. The maintainer reports unauthenticated access within the…
GHSA-xwmw-prc4-v3cr describes MCP-delegated tokens accepted by broader application APIs because issuer validation did not establish audience authority. Client authorization also lacked explicit consent. The maintainer…
CVE-2026-87015 concerns late-bound connection state: tool callables retained their own headers but read a shared cookie variable after connection processing finished. A maintainer-described controlled observation…
CVE-2026-59219 documents inconsistent session invalidation: HTTP authentication consulted revocation state, while realtime authentication checked only token signature and expiry. The reported local comparison shows…
GHSA-2rr4-q6pg-m5g3 documents a shared-policy input mismatch: browser sign-in supplied identity-token claims, while token exchange supplied only provider user information. Missing role evidence preserved an old role.…
Defines a high-security OAuth profile with coordinated requirements for confidential clients, authorization servers, and resource servers. Connects sender-constrained tokens and authorization-request integrity with the…
GHSA-33jq-x32c-3ccw describes webhook authority surviving deletion of its creator. Account cleanup omitted webhook subscriptions, while delivery trusted their enabled state. The maintainer-published report describes a…
Explains account-bound recovery challenges, limited lifetime and reuse, consistent responses, attempt controls, notifications and post-reset session handling.
Practical design guidance covering least privilege, deny-by-default behavior, consistent per-request decisions, failure handling, logging, and authorization regression tests.
OWASP explains origin checks, expected message formats and treating exchanged content as data. These controls address different assumptions at browser communication boundaries.
Distinguishes application-issued session identifiers from client-selected values. Explains renewing identifiers at login and other privilege changes, retiring previous identifiers, and separating anonymous tracking from…
Research on CVE-2026-29000 describes an authentication boundary failure: successful decryption could allow claims to become an authenticated profile without mandatory signature validation. The researcher reports…
CVE-2026-59151 concerns token issuance selecting a tenant from an asserted email domain instead of retaining the validated SAML configuration. Maintainers describe potential cross-tenant account takeover. Their…
GHSA-8r6w-3qq5-4p4r describes an authorization mismatch between the Panel and Wings. Tokens established an authenticated user and server context without adequately separating operation purpose. The maintainer-published…
Compares browser-only OAuth clients, token-mediating backends, and backend-for-frontend architectures through their different token-custody and session boundaries. Separates protection of token material from the…
Consensus guidance updating OAuth's security model with deployment experience, stronger protocol requirements, and deprecated insecure patterns. A primary reference for identity integration reviews.
CVE-2026-28514 concerned asynchronous password verification in the enterprise account service. The authentication decision treated an unfinished validation object as success instead of using its eventual result. The…
The maintainer describes inconsistent escaping between XML attribute and element-text contexts during SAML assertion generation. User-controlled profile values could change assertion structure before the identity…
CVE-2026-26004 concerned a missing organization constraint in event retrieval. A permission check on the active organization did not establish ownership of the requested object. GitHub Security Lab reports…
Studies account linking across multi-app integration platforms and identifies inconsistent app identity as a trust-boundary problem. Proposes app-specific authorization-context binding.
Studies a cross-layer authentication failure: shared TLS session-ticket infrastructure can preserve cryptographic session state without preserving the intended virtual-host identity and client-authentication policy. The…
A qualitative lab study of 31 participants across three services found that unclear passkey labels, notifications and recovery interfaces obstructed complete account remediation. Conceptual boundary: proof that a…
GHSA-7wjf-49rm-77gx describes incoming session identifiers being used as storage keys without validation. Constrained generation did not constrain values returning from the client. The maintainer reports read, overwrite…
Connected collection
Editorial conceptual model derived from the linked cases and official guidance; not a vendor architecture diagram or an exploitation sequence.
Original defensive model combining OWASP messaging and authorization guidance with the linked historical cases. These are independent design checks, not a vendor patch diagram or an operational reproduction.
Editorial conceptual model derived from the linked cases and official guidance; not a vendor architecture diagram or an exploitation sequence.
Editorial conceptual model derived from the linked cases and official guidance; not a vendor architecture diagram or an exploitation sequence.
Related learning follows the topic crosswalk or an explicit diagram relationship. It does not classify a resource as a finding. Topics overlap, so their counts should not be added together.
GitHub snapshot 2026-10-04
53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software
| / | Focus search on this page |
| Ctrl K | Search everything (command palette) |
| 1-9 | Library, Generator, Playbooks, Gadgets, Checklists, Payloads, Bypasses, Utilities, Reports |
| 0 | AI / MCP connector |
| j / k | Move selection down / up |
| Enter | Expand / open selected |
| c | Copy primary command of selected |
| f | Toggle favorite on selected tool |
| Esc | Clear search / close |