PT-2026-69131 · Unknown · Pathling Server

CVE-2026-47660

·

Published

2026-08-07

·

Updated

2026-08-07

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Pathling Server versions prior to 2.0.0
Description The bulk-submit operation allows an authorized submitter to provide an oauthMetadataUrl parameter that is not validated against the pathling.bulkSubmit.allowableSources list. This allows the OAuth flow to trust metadata and the token endpoint from a location chosen by the caller, subsequently building outbound OAuth client authentication using the submitter's stored credentials.
Recommendations Update Pathling Server to version 2.0.0.

Exploit

Fix

Insufficiently Protected Credentials

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47660
GHSA-245H-C573-9VR5

Affected Products

Pathling Server