What is CVE-2026-23922?
This vulnerability allowed a Super Admin to leak the OAuth 'Client secret' in the email media integration by setting a malicious 'Token endpoint', even though the secret could not be read after saving. The issue was mitigated by resetting the 'Client secret' upon changing the 'Token endpoint'.
Azərbaycanca: Bu zəiflik, e-poçt media inteqrasiyasında Super Admin istifadəçinin OAuth 'Client secret' məlumatını, zərərli 'Token endpoint' təyin edərək oxumasına imkan verirdi. 'Client secret' artıq yadda saxlandıqdan sonra oxuna bilmədiyi üçün təhlükəsizlik problemi yaranır. Həll olaraq 'Token endpoint' dəyişdirilərkən 'Client secret' sıfırlanır.
FAQ2
In which component was CVE-2026-23922 discovered and what privileged user is required?
This vulnerability was discovered in the email media integration and requires a Super Admin user for exploitation.
What mitigation was applied for CVE-2026-23922?
The vulnerability was mitigated by resetting the OAuth 'Client secret' upon changing the 'Token endpoint'.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.