Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-72561

HIGH NVD
CVSS Score 8.8
Severity HIGH
Published Aug 11, 2026
Vendor unknown

Description

A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-administrative user to reconfigure the platform global OIDC/SSO settings via an unprotected configuration endpoint. The endpoint performs no administrative role check before applying new OIDC issuer settings. An attacker can redirect all SSO logins to an attacker-controlled identity provider, enabling credential harvesting for all platform users.

References