
CVE-2026-40946 Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider unconditionally sets SkipClientIDCheck: true in the go-oidc verifi… https://www.cve.org/CVERecord?id=CVE-2026-40946
Post summary
The text reports a new vulnerability (CVE‑2026‑40946) in Oxia’s OIDC provider that unconditionally allows SkipClientIDCheck: true, enabling potential authentication bypass.

