
🚨 CVE-2026-33757: OpenBao lacks user confirmation ... Silent OIDC token hijacking via callback polling - attackers can remotely phish victims into auto-authenticating to att... https://zerodaysignal.com/vulnerability/CVE-2026-33757 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The tweet announces the discovery of CVE-2026-33757, describing a silent OIDC token hijacking flaw in OpenBao and linking to a detailed vulnerability page.



