Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-57807: miniOrange OAuth SSO Client: Password Recovery Bypass Risk
CVE-2026-57807
CVE-2026-57807
Summary
A security issue in miniOrange's OAuth Single Sign On (SSO) software allows attackers to bypass authentication using an alternative method. This affects all versions of the OAuth SSO client up to 38.5.8. It's essential to update to a fixed version to prevent unauthorized access to your system.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| miniorange security software pvt ltd. | oauth single sign on - sso (oauth client) | <= 38.5.8 |
Original title
WordPress OAuth Single Sign On - SSO (OAuth Client) plugin <= 38.5.8 - Broken Authentication vulnerability
Original description
Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploitation.
This issue affects OAuth Single Sign On - SSO (OAuth Client): from n/a through 38.5.8.
This issue affects OAuth Single Sign On - SSO (OAuth Client): from n/a through 38.5.8.
mitre CVSS3.1
9.8
Vulnerability type
CWE-288
Authentication Bypass Using Alternate Path
Published: 10 Jul 2026 · Updated: 21 Jul 2026 · First seen: 10 Jul 2026