CVE-2026-12740Disclosure

LOWCVSS 8.1 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter. RequestTokenV2 builds the provider authorization redirect without issuing a state value, and AccessTokenV2 exchanges the callback code and registers the resulting token into the session (register_session) without verifying that the callback corresponds to an authorization request this session initiated. Any application that uses this middleware for OAuth 2.0 login is exposed to login cross-site request forgery: because the callback is not bound to the session that began the flow, an attacker who starts an authorization with their own provider account can deliver the resulting callback to a victim, causing the victim's session to complete the attacker's authorization and associating the attacker's provider identity and access token with that session. Where the application persists this as an account link, the attacker may retain access to the victim's account through their own provider credentials.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-07-05); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-07-04: 1Mentions · 2026-07-05: 3Mentions · 2026-07-06: 1Active Exploitation · 2026-07-05: 1Technical Details · 2026-07-04: 1Technical Details · 2026-07-05: 1Technical Details · 2026-07-06: 107-0407-0507-06
Signal classification2 categories
Disclosure
480.0%
Active Exploitation
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-07-041
Disclosure1
2026-07-053
Active Exploitation1Disclosure2
2026-07-061
Disclosure1
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-12746: Dancer2::Plugin::Auth::OAuth::Provider before 0.23 do not support the OAuth 2.0 state parameter https://www.openwall.com/lists/oss-security/2026/07/04/9 CVE-2026-12740: Plack::Middleware::OAuth through 0.10 do not support the OAuth 2.0 state parameter https://www.openwall.com/lists/oss-security/2026/07/04/10

    Post summary

    This post announces two new CVEs affecting Perl modules that lack OAuth 2.0 state parameter support; no PoC, exploit, patch, or active exploitation details are provided.

    10010339
    4.7K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting Plack::Middleware::OAuth (CVE-2026-12740) https://vuldb.com/vuln/376354/cti

    Post summary

    The brief notice indicates that attackers are actively targeting CVE-2026-12740, but provides no proof of concept, exploit code, technical details, or patch information.

    00001134
    2.3K followersView on X
  • DFIR Lab@DFIR_Lab
    Disclosure

    🚨 HIGH SEVERITY: CVE-2026-12740 (CVSS 8.1) Plack::Middleware::OAuth ≤0.10 for Perl lacks OAuth 2.0 state parameter support, enabling login CSRF attacks. Attackers can link their provider identity to victim sessions. #CVE #Vulnerability #PatchNow https://t.co/brCiZAZlBF

    Post summary

    The post announces CVE‑2026‑12740, highlighting a login‑CSRF flaw in Plack::Middleware::OAuth due to missing OAuth 2.0 state support, but it provides no PoC, exploit code, or active exploitation details.

    0000047
    64 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-12740 Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter. RequestTokenV2 builds the provider authorization redirect witho… https://www.cve.org/CVERecord?id=CVE-2026-12740 ----- Traducción: CVE-2026-12740 Pla… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-12740, providing a technical detail about missing OAuth 2.0 state support, but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000039
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-12740 Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter. RequestTokenV2 builds the provider authorization redirect witho… https://www.cve.org/CVERecord?id=CVE-2026-12740

    Post summary

    The post announces CVE‑2026‑12740, noting that Plack::Middleware::OAuth up to 0.10 lacks OAuth 2.0 state parameter support, but offers no exploitation, patch, or PoC details.

    00000590
    57.7K followersView on X

Explore more