CVE Database
/

CVE-2026-3432

Back to search

CVE-2026-3432

Published: Mar 2, 2026

Modified: Mar 2, 2026

PUBLISHED

Description

On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided with `credentialAccountUserId` and `providerId` parameters. An unauthenticated attacker can retrieve OAuth access tokens for any user by supplying their user ID and a provider name, effectively stealing credentials to third-party services.

VendorProductVersions

SimStudioAI

sim

affected
0 - < 0.5.74

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now