CVE-2026-12746Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter. The authentication_url method builds the provider authorization redirect without issuing a state value, and the callback method exchanges the callback code and registers the resulting token into the session without verifying that the callback corresponds to an authorization request this session initiated. Any application that uses this plugin for OAuth 2.0 login is exposed to login cross-site request forgery: because the callback is not bound to the session that began the flow, an attacker who starts an authorization with their own provider account can deliver the resulting callback to a victim, causing the victim's session to complete the attacker's authorization and associating the attacker's provider identity and access token with that session. Where the application persists this as an account link, the attacker may retain access to the victim's account through their own provider credentials.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-07-05)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-04: 1Mentions · 2026-07-05: 2Technical Details · 2026-07-05: 207-0407-05
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-041
Disclosure1
2026-07-052
Disclosure2
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-12746: Dancer2::Plugin::Auth::OAuth::Provider before 0.23 do not support the OAuth 2.0 state parameter https://www.openwall.com/lists/oss-security/2026/07/04/9 CVE-2026-12740: Plack::Middleware::OAuth through 0.10 do not support the OAuth 2.0 state parameter https://www.openwall.com/lists/oss-security/2026/07/04/10

    Post summary

    The text discloses that Dancer2::Plugin::Auth::OAuth::Provider (<0.23) and Plack::Middleware::OAuth (≤0.10) lack OAuth 2.0 state parameter support, without specifying any exploit, patch, or active exploitation details.

    10010339
    4.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-12746 Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter. The authentication_url method builds the provider … https://www.cve.org/CVERecord?id=CVE-2026-12746

    Post summary

    The post announces CVE‑2026‑12746, noting that Dancer2::Plugin::Auth::OAuth::Provider before version 0.23 lacks OAuth 2.0 state support, but offers no PoC, exploit code, or patch details.

    00001807
    57.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-12746 Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter. The authentication_url method builds the provider … https://www.cve.org/CVERecord?id=CVE-2026-12746 ----- Traducción: CVE-2026-12746 Dan… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-12746, noting that Dancer2::Plugin::Auth::OAuth::Provider versions prior to 0.23 do not support the OAuth 2.0 state parameter, without presenting exploitation evidence or remediation.

    0000039
    91 followersView on X

Explore more