CVE-2026-3432Disclosure(sim / sim)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch sim sim systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided with `credentialAccountUserId` and `providerId` parameters. An unauthenticated attacker can retrieve OAuth access tokens for any user by supplying their user ID and a provider name, effectively stealing credentials to third-party services.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sim

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 3d ago at 3 mentions (2026-03-02); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
sim

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-02: 3Mentions · 2026-03-03: 1Mentions · 2026-03-06: 1Mentions · 2026-03-07: 1Patch / Workaround · 2026-03-03: 1Technical Details · 2026-03-02: 3Technical Details · 2026-03-03: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 103-0203-0303-0603-07
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-023
Disclosure3
2026-03-031
Patch1
2026-03-061
Disclosure1
2026-03-071
Disclosure1
Full discourse6 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3432 (CVSS:9.3, CRITICAL) is Analyzed. On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all author..https://nvd.nist.gov/vuln/detail/CVE-2026-3432 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet notes that CVE‑2026‑3432 is a critical authorization‑bypass flaw in SimStudio versions below 0.5.74, affecting the /api/auth/oauth/token endpoint, as documented in the NVD record.

    0000027
    173 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 SimStudio, Missing Authorization, #CVE-2026-3432 (CRITICAL) https://dailycve.com/simstudio-missing-authorization-cve-2026-3432-critical/

    Post summary

    The post announces a critical missing‑authorization vulnerability (CVE‑2026‑3432) in SimStudio with minimal technical details and no information on PoC, exploits, or remediation.

    0000039
    164 followersView on X
  • Fernando Karl@fernandokarl
    Patch

    🚨 Atenção, profissionais de segurança! A falha em SimStudio (<0.5.74) permite o roubo de tokens OAuth sem autenticação. Atualize para a versão 0.5.74 e implemente medidas de mitigação imediatas! 🔒💻 Saiba mais: https://www.tenable.com/cve/CVE-2026-3432 #CyberSecurity #Vulnerability #OAuth

    Post summary

    The post highlights CVE‑2026‑3432 in SimStudio, noting it permits unauthenticated OAuth token theft, and urges users to upgrade to version 0.5.74 and apply mitigations.

    0000063
    255 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3432 SimStudio OAuth Token Theft Vulnerability in Versions Below 0.5.74 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3432

    Post summary

    A new OAuth token theft vulnerability (CVE-2026-3432) affecting SimStudio versions below 0.5.70 has been disclosed.

    0000047
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3432 On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided with `credentialAcc… https://www.cve.org/CVERecord?id=CVE-2026-3432 ----- Traducción: CVE-2026-3432 En … http://infoflow.cloud`

    Post summary

    The post announces a new vulnerability (CVE‑2026‑3432) in SimStudio, detailing an authorization bypass in the /api/auth/oauth/token endpoint for versions below 0.5.74, without providing a PoC, exploit, or patch information.

    0000032
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3432 On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided with `credentialAcc… https://www.cve.org/CVERecord?id=CVE-2026-3432

    Post summary

    The text discloses CVE-2026-3432, a vulnerability in SimStudio versions below 0.5.74 where the /api/auth/oauth/token endpoint allows bypassing authorization checks via a specific code path.

    00000253
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsimsim---

Explore more