Tag
critical
advisory
Auth.js (next-auth) v5 Configuration Error Leads to Authentication Bypass
2 TTPsA critical configuration error vulnerability in `next-auth` (Auth.js) v5 applications, specifically versions v5.0.0-beta.0 through v5.0.0-beta.31, can lead to a 'fail-open' state where server-side configuration issues cause the `auth` object to be populated with an error instead of `null`, effectively bypassing authentication checks and granting unauthorized access to protected resources.
next-auth v5.0.0-beta.0 to v5.0.0-beta.31
authentication-bypass
configuration-error
web-application
security-vulnerability
2t
high
advisory
CVE-2026-59261 - OpenClaw Credential Exposure via Workspace Dotenv Files
1 TTP 1 CVEA critical vulnerability, CVE-2026-59261, in OpenClaw before version 2026.5.28, allows attackers with lower-trust access to configured input paths to expose sensitive provider credentials by leveraging workspace dotenv files that override legitimate configurations, leading to unauthorized access to sensitive data.
OpenClaw
credential-exposure
vulnerability
configuration-error
1t
1c