Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
937 articles · 105107 vulns · 38/41 feeds (7d)
← Back to list
—
CVE-2026-3531
Drupal · OpenID Connect OAuth client

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal OpenID Connect / OAuth client allows Authentication Bypass.This issue affects OpenID Connect / OAuth client: from 0.0.0

Description

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal OpenID Connect / OAuth client allows Authentication Bypass.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0.

Affected Products

VendorProductVersions
DrupalOpenID Connect OAuth client1.4.x

References

  • https://www.drupal.org/sa-contrib-2026-026

Related News (1 articles)

Tier C
VulDB4h ago
CVE-2026-3531 | OpenID Connect OAuth client up to 1.4.x on Drupal authentication bypass (sa-contrib-2026-026)
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
CWECWE-288
Published3/26/2026
Last enriched2h agov2
Trending Score20
Source articles1
Independent1
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Version History

v2
Last enriched 2h ago
v2Tier C2h ago

Updated vendor to Drupal, product to OpenID Connect OAuth client, affected versions to 1.4.x, severity to CRITICAL, and patch available to version 1.5.0.

vendorproductaffectedVersionspatchAvailable
via VulDB
v13h ago

Initial creation