{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/maxkey/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-67345"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MaxKey (4.1.12)"],"_cs_severities":["medium"],"_cs_tags":["oauth","identity-management","cve-2026-67345"],"_cs_type":"advisory","_cs_vendors":["MaxKey"],"content_html":"\u003cp\u003eMaxKey versions through 4.1.12 contain a security vulnerability in the DefaultRedirectResolver.hostMatches() method. The issue stems from insufficient validation of redirect URIs during the OAuth 2.0 authorization process. Specifically, the application fails to enforce proper dot-boundary anchoring when comparing the provided redirect_uri against registered URIs. This flaw allows an attacker to supply a crafted redirect_uri that shares a hostname suffix with a legitimate registered URI, effectively bypassing validation checks. By utilizing social engineering to entice a victim to initiate an authorization request via a malicious link, an attacker can cause the authorization server to send the authorization code to an attacker-controlled endpoint. The attacker then exchanges this code for an access token, resulting in unauthorized access to the victim's account and identity. Organizations using MaxKey 4.1.12 or earlier should apply the fix provided in commit ddbb72f.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote, unauthenticated attackers to hijack OAuth 2.0 authorization codes. This leads to the unauthorized acquisition of access tokens, enabling the attacker to impersonate the victim, access protected resources, and potentially escalate privileges within the environment. This affects all deployments of MaxKey relying on the standard OAuth 2.0 authorization flow.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade MaxKey instances to a version containing the fix for CVE-2026-67345 (commit ddbb72f).\u003c/li\u003e\n\u003cli\u003eReview application logs for unusual redirect_uri patterns in OAuth authorization requests, specifically checking for domains that match the suffix of authorized clients without proper sub-domain or TLD isolation.\u003c/li\u003e\n\u003cli\u003eAudit all registered OAuth 2.0 client redirect URIs in MaxKey to ensure they are fully qualified and follow strict matching standards.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-30T15:33:28Z","date_published":"2026-07-30T15:33:28Z","id":"https://feed.craftedsignal.io/briefs/2026-07-maxkey-oauth-vuln/","summary":"MaxKey versions through 4.1.12 are vulnerable to OAuth 2.0 authorization code hijacking due to improper host boundary checks in the DefaultRedirectResolver component.","title":"Insufficient Redirect URI Validation in MaxKey","url":"https://feed.craftedsignal.io/briefs/2026-07-maxkey-oauth-vuln/"}],"language":"en","title":"CraftedSignal Threat Feed - MaxKey","version":"https://jsonfeed.org/version/1.1"}