What is CVE-2026-55987?
CVE-2026-55987 allows an OAuth2 sign-in to reactivate an administrator-deactivated account on authentication sources that lack refresh tokens, representing an incomplete fix for issue #38009. Affected administrators should immediately apply the complete patch and enforce strict account lifecycle monitoring.
Azərbaycanca: CVE-2026-55987 autentifikasiya mənbələrində (auth sources) admin tərəfindən deaktiv edilmiş hesabı, refresh token-lərin olmadığı halda OAuth2 ilə giriş zamanı yenidən aktivləşdirir. Bu, CVE-38009 üçün natamam düzəlişdən qaynaqlanır. Təsirə məruz qalan sistemlərin administratorları dərhal müvafiq yenilənməni tətbiq etməli və hesab aktivliyi monitorinqini gücləndirməlidir.
FAQ2
Under what conditions does CVE-2026-55987 cause a deactivated account to be reactivated?
CVE-2026-55987 causes an administrator-deactivated account to be reactivated during OAuth2 sign-in on authentication sources that lack refresh tokens.
What is the root cause of the CVE-2026-55987 vulnerability?
This vulnerability stems from an incomplete fix for issue #38009.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.