What is CVE-2026-66884?
A Cross-Site Request Forgery vulnerability in the oidcc_plug library's AuthorizationCallback module allows an attacker to force a victim's browser to complete an authorization flow without their knowledge. Affected applications should immediately apply the security update provided by the maintainers.
Azərbaycanca: Bu, Erlang Ecosystem Foundation-un oidcc_plug kitabxanasının AuthorizationCallback modulunda aşkarlanmış Cross-Site Request Forgery zəifliyidir. Təcavüzkar istifadəçinin xəbəri olmadan onun adından icazə axınını tamamlaya bilər. Təsirə məruz qalan tətbiqlər üçün tərtibatçılar tərəfindən təqdim edilən təhlükəsizlik yeniləməsi dərhal tətbiq olunmalıdır.
Related CVEs
link basis: same weakness class CWE-352
FAQ1
What is the impact of CVE-2026-66884 in the oidcc_plug library?
It is a Cross-Site Request Forgery vulnerability. An attacker can complete an authorization flow on behalf of a user without their knowledge.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.