Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93354— Taskview Community Missing Authentication via OAuth Dynamic Client Registration

Quick assessment

Affected
Gimanh taskview-community
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Taskview Community 1.56.0 之前版本中存在一个缺失身份验证的漏洞,该漏洞允许未经验证身份的攻击者注册任意 OAuth 客户端,并通过利用默认启用且无需身份验证的 OAuth 2.0 动态客户端注册端点,接管用户账户。攻击者可以向该注册端点发送 POST 请求,以获取 client_id 和 client_secret,然后构造指向攻击者控制的重定向 URI 的恶意授权链接,从而捕获授权码,并将这些授权码交换为访问令牌,进而获得对受害者账户数据的完整 API 访问权限。

CVSS 8.1 · High EPSS 0.27% · P17

Affected Version Matrix 1

VendorProduct Version RangeStatus
Gimanh taskview-community < 1.56.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93354

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Taskview Community Missing Authentication via OAuth Dynamic Client Registration
Source: CVE Program / CVE List V5
Vulnerability Description
Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registration endpoint, which is enabled by default and requires no authentication. Attackers can send a POST request to the registration endpoint to obtain a client_id and client_secret, then craft a malicious authorization link pointing to an attacker-controlled redirect URI to capture authorization codes and exchange them for access tokens granting full API access to victim account data.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
不安全的默认资源初始化
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Gimanh taskview-community 0 ~ 1.56.0 -

II. Public POCs for CVE-2026-93354

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93354

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-93354 (1)

Vendor Pages for CVE-2026-93354 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-93354

No comments yet


Leave a comment