CVE-2026-33494Disclosure(ory / oathkeeper)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch ory oathkeeper systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2.0 are vulnerable to an authorization bypass via HTTP path traversal. An attacker can craft a URL containing path traversal sequences (e.g. `/public/../admin/secrets`) that resolves to a protected path after normalization, but is matched against a permissive rule because the raw, un-normalized path is used during rule evaluation. Version 26.2.0 contains a patch.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-23

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • oathkeeper

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 5 mentions (2026-03-26); latest day: 2
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
oathkeeper

Deep dive

Activity timeline8 mentions / 3d
01345Mentions · 2026-03-21: 1Mentions · 2026-03-26: 5Mentions · 2026-03-27: 2PoC Mentioned / Linked · 2026-03-26: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-21: 1Technical Details · 2026-03-26: 2Technical Details · 2026-03-27: 203-2103-2603-27
Signal classification2 categories
Disclosure
787.5%
General
112.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-211
Disclosure1
2026-03-265
Disclosure5
2026-03-272
Disclosure1General1
Full discourse8 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33494 ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2… https://www.cve.org/CVERecord?id=CVE-2026-33494

    Post summary

    A CVE-2026-33494 is disclosed for Ory Oathkeeper versions prior to 26.2, with no additional details on exploitation or remediation.

    00010180
    56.9K followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-33494 | CVSS 10.0 🔴 CVE-2026-33897 | CVSS 9.9 🔴 CVE-2026-33396 | CVSS 9.9 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post lists three high‑severity CVEs with their CVSS scores and links to a site for further details, but provides no information on exploits, patches, or active usage.

    0000034
    5.6K followersView on X
  • maruomosquit@maru1151157
    Disclosure

    🚨 CVE-2026-33494 (CVSS: 10.0) ORY Oathkeeper 26.2.0以前は、HTTPパストラバーサルによる認証回避が可能。攻撃者はパストラバーサルシーケンスを含むURLを構築し、ルール評価時に未正規化のパスを使用するため、保護されたパスにマッチする。26.2.0で修正。 https://maruomosquit.com/vulnerability/CVE-2026-33494/ #脆弱性 #セキュリティ

    Post summary

    A critical authentication bypass via HTTP path traversal in ORY Oathkeeper is disclosed, detailed with a CVSS score of 10, and corrected in version 26.2.0.

    0000050
    1.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33494 ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2… https://www.cve.org/CVERecord?id=CVE-2026-33494 ----- Traducción: CVE-2026-33494 ORY… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-33494, noting that versions of ORY Oathkeeper prior to 26.2 are affected, and directs readers to the official CVE record for more information.

    0000026
    65 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33494 - Critical ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2.0 are vulnerable to ... https://www.thehackerwire.com/vulnerability/CVE-2026-33494/ https://t.co/Rt6knJOPUU

    Post summary

    The tweet announces a critical CVE (CVE-2026-33494) affecting ORY Oathkeeper versions before 26.2.0 and provides a link to an external article for more information.

    0000024
    163 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-33494: CRITICAL] ORY Oathkeeper, an Identity & Access Proxy (IAP) and Access Control Decision API, has an authorization bypass vulnerability via HTTP path traversal in versions before 26.2.0. Updat...#cve,CVE-2026-33494,#cybersecurity https://cvefind.com/CVE-2026-33494

    Post summary

    The text announces a critical authorization bypass vulnerability in ORY Oathkeeper versions prior to 26.2.0, recommending users to upgrade to receive a fix.

    0000051
    605 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33494: Ory Oathkeeper has a path traver... Perfect CVSS 10.0 auth bypass via `../` sequences - Oathkeeper evaluates raw paths but normalizes for access, turning p... https://zerodaysignal.com/vulnerability/CVE-2026-33494 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-33494 reveals a path‑traversal based authentication bypass in Ory Oathkeeper, rated CVSS 10.0, with further details linked; no evidence of active exploitation or patching is mentioned.

    0000059
    169 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A path traversal authorization bypass (CVE-2026-33494) affects `Ory Oathkeeper`. This could lead to unauthorized access to protected resources. Monitor vendor advisories for a fix. #AuthBypass #PathTraversal #AppSec https://www.pulsepatch.io/posts/cve-2026-33494-ory-oathkeeper-path-traversal-authorization-bypass

    Post summary

    The post announces CVE‑2026‑33494, a path‑traversal authorization bypass in Ory Oathkeeper that may enable unauthorized access, and urges users to watch for vendor advisories.

    0000045
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apporyoathkeeper---

Explore more