PT-2026-84831 · Boruta · Boruta

CVE-2026-55221

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Boruta versions prior to 0.10.0
Description Boruta, a standalone authorization server implementing OAuth 2.0 and OpenID Connect, improperly records sensitive values in business event logs. This includes access tokens, refresh tokens, authorization codes, agent tokens, direct-post codes, ID tokens, VP tokens, and tokens sent to introspection or revocation endpoints. An attacker with access to the logs, log aggregation systems, or the administration log viewer could recover these credentials and use them until they expire or are revoked.
Recommendations Update to version 0.10.0.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55221
GHSA-PQWF-V25H-4874

Affected Products

Boruta