CVE-2026-85511
MEDIUM
NVD
CVSS Score
4.2
Severity
MEDIUM
Published
Sep 18, 2026
Vendor
unknown
Description
A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.