CVE-2026-40946Disclosure

LOWCVSS 9.2 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider unconditionally sets SkipClientIDCheck: true in the go-oidc verifier configuration, disabling the standard audience (aud) claim validation at the library level. This allows tokens issued for unrelated services by the same OIDC issuer to be accepted by Oxia. This vulnerability is fixed in 0.16.2.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-21); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-21: 1Mentions · 2026-04-26: 1PoC Mentioned / Linked · 2026-04-21: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-26: 104-2104-26
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-40946 Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider unconditionally sets SkipClientIDCheck: true in the go-oidc verifi… https://www.cve.org/CVERecord?id=CVE-2026-40946

    Post summary

    The text reports a new vulnerability (CVE‑2026‑40946) in Oxia’s OIDC provider that unconditionally allows SkipClientIDCheck: true, enabling potential authentication bypass.

    00000168
    57.3K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40946: Oxia: OIDC token audience valida... Hardcoded SkipClientIDCheck bypasses OIDC audience validation - any JWT from the same issuer grants full access regardl... https://zerodaysignal.com/vulnerability/CVE-2026-40946 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-40946, a hardcoded SkipClientIDCheck bypass in Oxia’s OIDC token audience validation, and links to a resource that likely contains a PoC, but no exploit code or patch is mentioned.

    0000090
    218 followersView on X

Explore more