What is CVE-2026-65635?
This vulnerability exists in the Elixir.Boruta.Openid module of the malach-it boruta library. Attackers can register OpenID Connect clients with administrative privileges via the dynamic client registration endpoint. Systems using the Boruta library should immediately apply relevant security patches.
Azərbaycanca: Bu zəiflik malach-it boruta kitabxanasının Elixir.Boruta.Openid modulunda aşkarlanıb. Təcavüzkarlar dinamik müştəri qeydiyyatı endpoint-i vasitəsilə admin hüquqlu OpenID Connect müştəriləri yarada bilərlər. Boruta kitabxanasını istifadə edən sistemlər dərhal müvafiq təhlükəsizlik yamalarını tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
In which library was CVE-2026-65635 discovered, and which specific module does it affect?
This vulnerability was discovered in the malach-it boruta library, within the Elixir.Boruta.Openid module.
How can attackers gain privileges through CVE-2026-65635?
Attackers can register OpenID Connect clients with administrative privileges via the dynamic client registration endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.