CVE-2026-43886 - Outline: OAuth Scope Validation Logic Error Allows Privilege Escalation to Wildcard API Access
CVE ID :CVE-2026-43886 Published : May 11, 2026, 10:22 p.m. | 43 minutes ago Description :Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, a logic error in OAuthInterface.validateScope() uses Array.some() to validate requested OAuth scopes, causing the fu
ORIGINAL SOURCE →via CVE Feed Latest
ADVERTISEMENT
⚡ STAY AHEAD
Events like this, convergence-verified across 689 sources, land in your inbox every Sunday. Free.
GET THE SUNDAY BRIEFING →RELATED · cyber
- [CYBER] Google Detects First AI-Generated Zero-Day Exploit
- [CYBER] Privacy watchdog wraps up probe into Coupang data leak, to decide penalty as early as June
- [CYBER] Pressure mounts on Canvas as data leak extortion deadline looms
- [CYBER] Developer of education tool Canvas issues apology after hack
- [CYBER] Double Canvas breach acknowledged as ShinyHunters sets new pay-or-leak deadline
- [CYBER] Nvidia GeForce NOW data breach confirmed — but luckily most of us will be safe, here's why