NONE · 0

CVE-2026-90452

Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker posit...

Vulnerability Description

Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker positioned on the network path between the proxy and the identity provider could impersonate the identity provider and issue forged authentication tokens accepted by the deployment.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-90452?

CVE-2026-90452 is a documented vulnerability. Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker posit...

How severe is CVE-2026-90452?

CVSS scoring is not yet available for CVE-2026-90452. Check NVD for updates.

Is there a patch for CVE-2026-90452?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.