PT-2026-26780 · Ory · Ory Oathkeeper

·

CVE-2026-33496

·

Published

2026-03-20

·

Updated

2026-07-30

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Ory Oathkeeper (affected versions not specified)
Description Ory Oathkeeper is susceptible to authentication bypass due to cache key confusion within the oauth2 introspection authenticator. The caching mechanism does not differentiate between tokens validated using distinct introspection URLs. An attacker can leverage a valid token to populate the cache and subsequently utilize the same token for rules associated with a different introspection server. This requires multiple oauth2 introspection authenticator servers configured with caching enabled, and the attacker must possess a valid token for one of these servers.
Recommendations Update to the patched version of Ory Oathkeeper. If an immediate update is not feasible, disable caching for oauth2 introspection authenticators.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33496
GHSA-4MQ7-PVJG-XP2R
GO-2026-4799
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:1135-1

Affected Products

Ory Oathkeeper