CVE-2026-34457Disclosure(oauth2_proxy_project / oauth2_proxy)

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch oauth2_proxy_project oauth2_proxy systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authentication bypass in deployments where OAuth2 Proxy is used with an auth_request-style integration (such as nginx auth_request) and either --ping-user-agent is set or --gcp-healthchecks is enabled. In affected configurations, OAuth2 Proxy treats any request with the configured health check User-Agent value as a successful health check regardless of the requested path, allowing an unauthenticated remote attacker to bypass authentication and access protected upstream resources. Deployments that do not use auth_request-style subrequests or that do not enable --ping-user-agent/--gcp-healthchecks are not affected. This issue is fixed in 7.15.2.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • oauth2_proxy

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • Peaked 2d ago at 4 mentions (2026-04-15); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Products
oauth2_proxy

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-04-14: 2Mentions · 2026-04-15: 4Mentions · 2026-04-23: 1Mentions · 2026-04-28: 1PoC Mentioned / Linked · 2026-04-14: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-04-23: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-14: 2Technical Details · 2026-04-15: 4Technical Details · 2026-04-23: 1Technical Details · 2026-04-28: 104-1404-1504-2304-28
Signal classification2 categories
Disclosure
675.0%
Patch
225.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-142
Disclosure1Patch1
2026-04-154
Disclosure4
2026-04-231
Patch1
2026-04-281
Disclosure1
Full discourse8 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical Authentication Bypass in #OAuth2Proxy. CVE-2026-34457 CVSS: 9.1. This health-check spoofing flaw can lead to unauthorized access to protected upstream resources. #Patch #Patch #Patch

    Post summary

    The tweet announces the discovery of a critical authentication bypass (CVE‑2026‑34457) in OAuth2Proxy, with a CVSS score of 9.1, highlighting health‑check spoofing that can grant unauthorized upstream access.

    01000167
    7.2K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-34457: CVE-2026-34457: Authentication Bypass via User-Agent Spoofing in OAuth2 Proxy OAuth2 Proxy versions prior to 7.15.2 are vulnerable to a critical authentication bypass (CWE-290) when configured with User-Agent-based health checks in an ... https://cvereports.com/reports/CVE-2026-34457

    Post summary

    CVE-2026-34457 exposes a critical authentication bypass in OAuth2 Proxy versions before 7.15.2 due to User-Agent spoofing in health checks; upgrading to 7.15.2 or later mitigates the issue.

    0000021
    36 followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 CRITICAL: CVE-2026-34457 (CVSS 9.1) - OAuth2 Proxy auth bypass in versions <7.15.2. Attackers can bypass authentication via crafted User-Agent in nginx auth_request deployments. Patch immediately! #CVE #Vulnerability #PatchNow https://t.co/YdwyCIhDy9

    Post summary

    The tweet alerts about the critical OAuth2 Proxy authentication bypass (CVE-2026-34457) with a CVSS of 9.1, emphasizes the exploit path via crafted User‑Agent, and urges immediate patching, but does not provide exploit code or evidence of active exploitation.

    0000056
    26 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34457 OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authentication bypass … https://www.cve.org/CVERecord?id=CVE-2026-34457

    Post summary

    CVE-2026-34457 identifies a configuration-dependent authentication bypass in OAuth2 Proxy versions older than 7.15.2, with no PoC, exploit, or patch details provided.

    0000073
    57.2K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    An authentication bypass (CVE-2026-34457) affects `OAuth2 Proxy` in auth_request mode. This flaw leverages health check User-Agent matching, leading to unauthorized access. Review configurations and monitor for updates. #AuthBypass #OAuth2Proxy #InfoSec https://www.pulsepatch.io/posts/cve-2026-34457-oauth2-proxy-authentication-bypass

    Post summary

    The post discloses an authentication bypass in OAuth2 Proxy (CVE-2026-34457) caused by health-check User-Agent matching, allowing unauthorized access, and advises reviewing configurations and staying alert for updates.

    0000038
    12 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-34457 Authentication Bypass in OAuth2 Proxy Versions Prior to 7.15.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34457

    Post summary

    The text announces CVE-2026-34457, detailing an authentication bypass in OAuth2 Proxy versions before 7.15.2, without mentioning PoC, exploit code, active use, or patches.

    0000045
    4.0K followersView on X
  • Red Hornet Intel@RedHornet_Intel
    Patch

    CVE-2026-34457 | oauth2-proxy | Authentication Bypass Description OAuth2 Proxy prior to 7.15.2 has a config-dependent auth bypass in auth_request integrations (e.g., nginx) with --ping-user-agent or --gcp-healthchecks enabled. Attackers send requests using the configured health check User-Agent, which are treated as successful health checks regardless of path, bypassing auth to access protected upstream resources. Severity: Critical Exploitation: Unknown Public PoC: Unknown Patch Available: Yes Affected Product: oauth2-proxy Affected Version: < 7.15.2 Sources Research: https://github.com/oauth2-proxy/oauth2-proxy/security/advisories/GHSA-5hvv-m4w4-gf6v Research: https://github.com/oauth2-proxy/oauth2-proxy/releases/tag/v7.15.2

    Post summary

    The advisory reports a critical authentication bypass in oauth2‑proxy (v<7.15.2), confirms a patch is available, but does not provide evidence of exploitation or a PoC.

    0000084
    8 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34457: OAuth2 Proxy: Health Check User-... Spoofing a health check User-Agent string grants full upstream access—trivial bypass that turns monitoring configs into... https://zerodaysignal.com/vulnerability/CVE-2026-34457 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A zero‑day flaw in OAuth2 Proxy lets attackers spoof the health‑check User‑Agent header and obtain full upstream access; no patch or active exploitation details are provided.

    0000072
    218 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appoauth2_proxy_projectoauth2_proxy---

Explore more