PT-2026-85218 · Medplum · Medplum

CVE-2026-44506

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Medplum versions 4.1.10 through 5.1.6
Description Medplum is a developer platform for healthcare applications. The '/oauth2/register' endpoint may expose the client secret of preconfigured OAuth clients defined in the defaultOAuthClients server configuration if a matching redirect uri is provided.
Recommendations Update to version 5.1.7.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44506
GHSA-CH8P-J6CM-R7W5

Affected Products

Medplum