CVE-2026-93354
Deferred Deferred - Pending Action

Taskview Community OAuth Client Registration Authentication Bypass

Vulnerability report for CVE-2026-93354, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: VulnCheck

Description

Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registration endpoint, which is enabled by default and requires no authentication. Attackers can send a POST request to the registration endpoint to obtain a client_id and client_secret, then craft a malicious authorization link pointing to an attacker-controlled redirect URI to capture authorization codes and exchange them for access tokens granting full API access to victim account data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-25
AI Q&A
2026-09-25
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
taskview community to 1.56.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1188 The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Taskview Community before version 1.56.0 has a missing authentication vulnerability in its OAuth 2.0 Dynamic Client Registration endpoint. This allows unauthenticated attackers to register arbitrary OAuth clients and hijack user accounts by sending a POST request to the registration endpoint to obtain client credentials. Attackers can then create malicious authorization links to capture authorization codes and exchange them for access tokens, gaining full API access to victim account data.

Detection Guidance

Check if the Taskview Community application is running and verify its version. If it is below 1.56.0, the system is vulnerable. Inspect network traffic for POST requests to the OAuth 2.0 Dynamic Client Registration endpoint (typically /register or similar). Look for unauthorized client registrations or unexpected OAuth client IDs/secrets being generated.

Impact Analysis

If you use Taskview Community before 1.56.0, attackers could take over your account by exploiting this vulnerability. They may gain access to your personal data, manipulate your account settings, or perform actions on your behalf without your consent. This could lead to data breaches, unauthorized access to sensitive information, or further compromise of connected systems.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's data protection principles and HIPAA's security requirements. Organizations may face regulatory fines, legal liabilities, and reputational damage due to non-compliance resulting from data breaches or unauthorized access caused by this flaw.

Mitigation Strategies

Upgrade Taskview Community to version 1.56.0 or later immediately. Disable the OAuth 2.0 Dynamic Client Registration endpoint if not required. Review and revoke any unauthorized OAuth clients. Monitor for suspicious activity such as unexpected client registrations or access token requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93354. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart