
CVE-2026-1842 HyperCloud versions 2.3.5 through 2.6.8 improperly allowed refresh tokens to be used directly for resource access and failed to invalidate previously issued access toke… https://www.cve.org/CVERecord?id=CVE-2026-1842
Post summary
CVE-2026-1842 exposes that HyperCloud versions 2.3.5–2.6.8 incorrectly allow refresh tokens to be used for direct resource access and fail to revoke existing access tokens, constituting a disclosure of a new authentication token misuse vulnerability.
